Trim a Sume connection to 3 media tools with allowed_tools

OpenAI's MCP tool accepts allowed_tools and require_approval. Limiting a Sume connection to generate_video, jobs_wait and jobs_result keeps the tool list short.

4 min readSume
All posts

OpenAI's remote MCP tool has an allowed_tools field and a require_approval setting of always, never or filtered. Sume's hosted server exposes a long tool list, including crawl, avatar, timeline and account tools. If your agent only makes video, point it at three tools: generate_video to submit, jobs_wait to wait, and jobs_result to fetch. The OpenAI page says there is no per-call fee for MCP and you pay tokens, so a shorter tool list is a token saving, though this post has no measured number for it.

The three tools

Sume tools for a video agent, docs read 2026-10-05
ToolKindGate
generate_videoPaididempotency_key required; dry_run, max_spend_usd optional
jobs_waitRead1-20 job_ids; default 50s, cap 55s
jobs_resultReadAlso takes job_ids; partial success is normal

The connection entry

The entry below uses only fields from OpenAI's page: server_url, allowed_tools, require_approval and authorization. The authorization value is not stored, so your server must send it on every request. Putting always on approval means a human sees each call, including the cheap waits. If your integration needs the filtered form, check the OpenAI page for its exact shape.

{
  "type": "mcp",
  "server_label": "sume",
  "server_url": "https://mcp.sume.com/mcp",
  "allowed_tools": ["generate_video", "jobs_wait", "jobs_result"],
  "require_approval": "always",
  "authorization": "<your Sume OAuth token or API key>"
}

What the credential must allow

Under OAuth mcp:read, paid tools are hidden, so generate_video will not be in the list even if your allowlist names it. Grant mcp:write at consent, or use an API key. Paid calls need an idempotency_key, and the docs recommend dry_run or generation_admission_preview before expensive bursts.

What you give up

  • No discovery. With three tools allowed, the agent cannot call catalog_list or video-router_models, so pin the model yourself or omit payload.model to route to sume/auto.
  • No uploads. Add assets_upload_url and assets_complete if the agent has to bring its own media.
  • No cancel. Add jobs_cancel if you want the agent to stop queued jobs.
  • Re-check the allowlist when you upgrade, since tool ids come from tools_list.

Measuring the effect

This post has no benchmark for the effect on tokens or latency and does not invent one. To measure it yourself, run the same prompt twice, once with no allowlist and once with the three tools, and compare the token usage reported by the OpenAI API and the wall-clock time to first tool call. Record the date and the number of tools in each run.

Also test a failure: remove jobs_result from the allowlist and confirm the agent stops with a clear message, not a loop. A short tool list should make the agent's options clearer, and the test confirms it.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume