Agent Builder: approve tool calls, keep the Sume session read-only
OpenAI says to enable approvals for reads and writes. A Sume MCP session with mcp:read only can't run paid or mutating tools.

OpenAI's guide to building agents safely tells you to always keep tool approvals on for MCP tools, for reads as well as writes, so you can review what data is being shared. That protects you from a bad call getting through unseen. For a Sume connection it is worth adding a second layer that does not depend on a person clicking: authorize the session with mcp:read only, so paid and mutating tools cannot run at all.
Guidance is from OpenAI's Agent Builder safety page, read on 2026-10-03; Sume's scopes are in MCP OAuth and API keys.
What does OpenAI recommend?
The page lists prompt injection and private-data leakage as the main risks when agents use tools and untrusted input, and says not to put untrusted variables into developer messages. It recommends keeping tool approvals on and using structured outputs between nodes. It also says built-in guardrails are not foolproof, so approvals remain the human check.
What does Sume add on the server?
Hosted MCP lives at https://mcp.sume.com/mcp with OAuth scopes mcp:read, which is required, and mcp:write, which is opt-in. On the consent screen read is locked on and write is off by default. With mcp:read only, the session sees read-only tools, and mutating or paid calls return insufficient_scope. Paid and write tools also require an idempotency_key.
| Layer | Who enforces it | Stops a paid call? |
|---|---|---|
| Tool approval in Agent Builder | A person reviewing each call | Only if they decline |
mcp:read OAuth session | Sume server | Yes, insufficient_scope |
max_spend_usd on the call | Sume server, when sent | Over the cap, yes |
How should I set it up?
- Connect the MCP server with read access first. Look up jobs and results with that.
- Add
mcp:writeonly for the workflow that must create things, and keep approvals on there. - Ask the agent to send
dry_run=truefirst on any expensive create. - Never pass user-supplied text through developer messages; use user messages, as OpenAI advises.
What does the OpenAI page not cover?
It does not describe any one vendor's scopes, so the table above is the Sume half. Read the consent screen when you connect: Read is locked on and Write is off, and you must turn Write on yourself. An API key, by contrast, sees the full tool set, so prefer OAuth for an Agent Builder connection that a person approves.
When do approvals still matter?
On a write session, an approval is the only thing that reads the arguments before a paid create runs. Keep it on. The scope limits what kinds of tools exist; the approval lets you see which one is about to run and with what spend cap.
Sources
Related posts
More in Integrations
- Pinterest catalog image_link: 1000x1500 minimum, video_link 2 GB
Pinterest's catalog needs image_link at 1000x1500 or more; each additional_image_link becomes its own Pin and video_link takes MP4, MOV or M4V up to 2 GB.
- Portkey MCP gateway: per-user tool allowlists for Sume write tools
Portkey's MCP gateway can enable or disable tools per user and log every call. Use it to keep Sume's paid tools from most users, on top of Sume's gates.
- PrestaShop combination images: one AI image per color
In PrestaShop you upload every image on the product, then tick which ones belong to each combination. Make one image per color from a packshot with Sume.
- Reddit catalog image_link: 500x500 minimum, 20 MB, JPG or PNG
Reddit Ads catalog rules for dynamic product ads: image_link 500x500 or more, 20 MB, JPG or PNG; titles over 35 characters may be cut. Fix photos with Sume.
Written by Sume