OpenAI Agents 0.23 MCP listing page limits and Sume tools_list

Agents SDK 0.23.0 adds configurable MCP listing page limits. For a Sume server: call tools_list once, then tools_schema for the one tool you need.

5 min readSume
All posts

OpenAI Agents SDK v0.23.0 added "configurable MCP listing page limits," and for Sume the practical move is the same one Sume's docs already give: list tools once with tools_list, then fetch only the contract you need with tools_schema. I could not confirm from the release notes which option name sets the limit or whether Sume paginates its list, so check both before relying on a number.

The openai-agents-python releases page and the v0.23.0 release, both read 2026-10-02, list v0.23.0 on October 2, 2026, with the MCP item numbered #5133 alongside session and sandbox changes. The notes give no more than that one line on the MCP change.

What does Sume return when an agent lists tools?

Sume's hosted MCP server is at https://mcp.sume.com/mcp. MCP tools and gates says to discover the live contract with tools_list and tools_schema and not to assume parity with the HTTP API. tools_list returns every tool visible in the session with safety metadata, and which tools are visible depends on auth.

What a session can see (read 2026-10-02, from MCP tools and gates)
Session authVisible tools
OAuth mcp:read onlyRead-only tools; mutating or paid calls return insufficient_scope
OAuth mcp:read plus mcp:writeFull hosted tool set
API keyFull hosted tool set

Why does list size matter to an agent?

The hosted inventory spans meta and health tools, account and catalog, jobs, assets, and paid generation (generate_image, generate_video, tts_create, and more), plus script_run. Every tool a client loads adds a description and schema to the model's context. A page limit in the SDK caps how much one list call pulls in, and a smaller visible set (read-only OAuth) caps what the model could even attempt.

Whether a cap helps depends on your agent: if it truncates the list, a tool the agent needs may be missing from the first page. Test with your own session, calling the SDK's list function and counting what returns.

How do I keep prompts small and calls correct?

Follow Sume's own example instruction and ask for one schema at a time:

  • Paid and write tools require idempotency_key; it is dedup, not human approval.
  • dry_run=true previews admission and cost without submitting; max_spend_usd is enforced only when you pass it.
  • Prefer generation_admission_preview before an expensive burst.
Call tools_schema with name "generate_image" and explain
idempotency_key and dry_run before submitting any paid generation.

How do I verify what my agent actually sees?

Connect the SDK to https://mcp.sume.com/mcp with your chosen auth, list the tools, and print the names. Compare that list with the one tools_list returns when you call it as a tool. If the SDK list is shorter, a limit or filter is in play; if the two match, your page limit is not truncating anything for this session.

Run the check twice, once under OAuth mcp:read and once with an API key. The first should show read-only tools and the second the full set. A missing generate_video under read-only OAuth is correct behaviour, and paid calls attempted there return insufficient_scope.

Call mcp_health as the first tool in a new session. It reports endpoint readiness, auth source and safety posture, which tells you in one call whether a gap in the list is a configuration problem or the way the session is scoped.

What does Sume not do about this?

Sume documents no paging parameter for tools_list that I found, and no filtered list by tool name; tools_schema takes one name. If your agent only needs three tools, filter in the SDK or give the agent a short allowlist. For approvals on the write tools, see OpenAI Agents SDK MCP require_approval for Sume write tools. Before you ship, read the live contract for every route you call at https://api.sume.com/reference/json, which Sume's docs name as the schema source of truth, and re-read the linked docs pages: limits, scopes and error codes change faster than blog posts do. Treat any number in this post as a snapshot dated 2026-10-02, and prefer the effective fields your own responses return, such as generation_limits, over a static table.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume