n8n MCP Client Tool: Tools to Include modes for Sume
n8n's MCP Client Tool can expose All, Selected, or All Except tools. How to pick the set for Sume so an AI Agent node reads freely but cannot spend by accident.

On n8n's MCP Client Tool node, set Tools to Include to Selected for Sume and tick the read tools plus only the one paid tool the workflow needs. The node offers three modes: All, Selected, and All Except. With a Sume API key the server lists its full hosted tool set, so All would hand an AI Agent every paid tool.
What are the three modes?
The n8n docs describe All as exposing every tool the server gives, Selected as choosing the tools to expose, and All Except as choosing the tools to avoid sharing. The node also supports Bearer, Generic header, multiple headers and OAuth2 authentication, or none.
| Mode | Effect on Sume | When to use |
|---|---|---|
| All | Agent sees every tool the credential can see | Read-only OAuth session only |
| Selected | Agent sees only ticked tools | Production workflows |
| All Except | Everything but your exclusions | Prototyping with a key |
Which Sume tools belong in a read-only set?
Sume's docs list the free reads: tools_list, tools_schema, mcp_health, account_me, balance_get, catalog_list, and the jobs reads jobs_list, jobs_get, jobs_status, jobs_result and jobs_wait. Assets reads are assets_list, assets_get and assets_download_url.
Paid examples are generate_image, generate_video, music_create, tts_create and avatars_create. An OAuth session without mcp:write never sees the write and paid tools, which is a second layer of control behind the n8n selection.
What else should the agent prompt say?
The n8n page labels the connection field as an SSE endpoint, while Sume documents a streamable HTTP endpoint. Test the connection with mcp_health before building around it, and see the related posts for how that field behaves.
- Call tools_schema before the first paid call.
- Send dry_run true first; it previews cost and does not submit.
- Include a stable idempotency_key per workflow execution, and an optional max_spend_usd.
- Use jobs_wait in slices of at most 55 seconds.
How should the workflow be wired?
Connect the MCP Client Tool to an AI Agent node, choose the authentication option that matches your credential (Bearer for a Sume API key, or OAuth2 if you have set up an OAuth client), and then set Tools to Include. Run the workflow once with a prompt that only asks the agent to list what it can do. The answer shows exactly which Sume tools survived your selection.
If a tool is missing, check two things in order: whether you ticked it in the n8n node, and whether the Sume credential can see it. A read-only OAuth session hides write and paid tools no matter what n8n selects. A key session shows them, so the n8n selection becomes the only filter, which is why Selected is the safer mode for anything that runs on a schedule.
Before you rely on any of this in a team setting, test it once end to end with a throwaway prompt. Call mcp_health, call tools_list, and run one dry_run against a paid tool. Compare the tool count with what you expected for your credential. If a read-only OAuth session lists more than you expected, or a key session lists fewer, stop and recheck which credential the client is actually sending. Sume's mcp_health response reports the auth source, which settles the question quickly without guessing.
Sources
Related posts
More in Integrations
- Neovim mcphub.nvim: Sume hosted MCP with autoApprove for read tools
mcphub.nvim reads remote MCP servers from servers.json. Add Sume with a Bearer header, autoApprove only read tools, and leave paid generation to confirm.
- Slack MCP draft message plus Sume: post a generated clip after review
Slack's MCP server can draft, schedule and send messages. Pair it with Sume's hosted MCP: generate the clip, post the durable media.sume.com link as a draft.
- Cline cline_mcp_settings.json for Sume: streamableHttp and cline mcp
Where Cline keeps remote MCP config, the streamableHttp entry for Sume's hosted server, and the cline mcp wizard that reruns browser authorization.
- Tavus adds Agora support; Sume has no real-time transport to plug in
Tavus announced official Agora support on Oct 8. Sume has no WebRTC, Agora or live-stream path for avatars; it returns finished clips as job results.
Written by Sume