Notion custom MCP connections: add Sume read-only first

Notion 3.7 adds custom MCP connections with approvals. Connect Sume's hosted MCP endpoint with the default read-only OAuth scope, then turn on writes.

5 min readSume
All posts

Can you connect Sume to Notion's agent as a custom MCP connection? Sume runs a hosted MCP endpoint at https://mcp.sume.com/mcp, and Notion 3.7, released September 15, adds custom MCP connections with approval confirmations, in beta for Business and Enterprise workspaces (read 2026-10-04). Put those together and the safest first connection is read-only: the endpoint's OAuth flow defaults to a read-only scope, and you decide separately whether Notion's agent may write.

This post covers what to enter, what the consent page asks, and the first three calls that tell you the connection works.

What Notion 3.7 changed

The release notes describe custom MCP connections, with GitHub and Amplitude as examples, and approval confirmations so that a person can accept or decline what the agent is about to do. The same release adds Agent Skills, sub-agents and post-meeting automation. The custom connection feature is flagged as beta for Business and Enterprise, so check your plan before planning around it.

The Notion developers changelog separately records that on September 28 the limits for MCP calls were raised to 20 search calls and 20 query calls per 10 seconds per connection (read 2026-10-04). Those limits matter if the agent loops over Sume job status, which the post on Notion MCP call limits and Sume job polling covers.

The Sume side: endpoint and scopes

Sume's hosted MCP server is reached at https://mcp.sume.com/mcp. Sign-in uses OAuth, and the default grant is read-only, the mcp:read scope. The consent page has a Write toggle; turning it on grants mcp:write. There is no separate paid scope, so writes are the line to think about: a write tool can start a job that spends credits.

An API key is the other way in, and it gives the full tool set. For a workspace-wide agent that many people can talk to, OAuth with read-only is the better starting point.

Sume hosted MCP access options (read 2026-10-04)
OptionWhat it grantsGood for
OAuth, Write off (default)mcp:readFirst connection, browsing, status checks
OAuth, Write onmcp:read and mcp:writeAn agent that should start jobs
API keyFull tool set; paid or write calls need idempotency_keyServers and automation you control

Three first calls

After the connection is added and you have signed in, ask Notion's agent to run these in order, and read the approval prompts as they appear. The goal is to confirm the connection before it can change anything.

If a call fails, read the error envelope: Sume errors come back as {error:{code,message,request_id}}, and the request_id is what you need to quote.

  • mcp_health, which confirms the server is reachable.
  • tools_list, which shows exactly which tools your scope exposes. With Write off, expect the write tools to be absent or refused.
  • account_me, which confirms whose account the connection acts for.

Turning writes on safely

When you do enable Write, keep Notion's approval confirmations on for the tools that start jobs. Sume's paid and write tools expect an idempotency_key, so a repeated approval does not create a second paid job, and the tools offer dry_run and max_spend_usd so the agent can preview or cap a request. Ask the agent to use a dry run first, and set a spend ceiling in the instruction you give it.

The post on checking tool access with tools_list walks through the preflight in more detail. If a connection ever behaves oddly, revoke it on Sume's side and re-add it; revoking an OAuth grant is cleaner than hunting through what an agent did.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume