Trim a Sume connection to 3 media tools with allowed_tools
OpenAI's MCP tool accepts allowed_tools and require_approval. Limiting a Sume connection to generate_video, jobs_wait and jobs_result keeps the tool list short.

OpenAI's remote MCP tool has an allowed_tools field and a require_approval setting of always, never or filtered. Sume's hosted server exposes a long tool list, including crawl, avatar, timeline and account tools. If your agent only makes video, point it at three tools: generate_video to submit, jobs_wait to wait, and jobs_result to fetch. The OpenAI page says there is no per-call fee for MCP and you pay tokens, so a shorter tool list is a token saving, though this post has no measured number for it.
The three tools
| Tool | Kind | Gate |
|---|---|---|
generate_video | Paid | idempotency_key required; dry_run, max_spend_usd optional |
jobs_wait | Read | 1-20 job_ids; default 50s, cap 55s |
jobs_result | Read | Also takes job_ids; partial success is normal |
The connection entry
The entry below uses only fields from OpenAI's page: server_url, allowed_tools, require_approval and authorization. The authorization value is not stored, so your server must send it on every request. Putting always on approval means a human sees each call, including the cheap waits. If your integration needs the filtered form, check the OpenAI page for its exact shape.
{
"type": "mcp",
"server_label": "sume",
"server_url": "https://mcp.sume.com/mcp",
"allowed_tools": ["generate_video", "jobs_wait", "jobs_result"],
"require_approval": "always",
"authorization": "<your Sume OAuth token or API key>"
}What the credential must allow
Under OAuth mcp:read, paid tools are hidden, so generate_video will not be in the list even if your allowlist names it. Grant mcp:write at consent, or use an API key. Paid calls need an idempotency_key, and the docs recommend dry_run or generation_admission_preview before expensive bursts.
What you give up
- No discovery. With three tools allowed, the agent cannot call
catalog_listorvideo-router_models, so pin the model yourself or omitpayload.modelto route tosume/auto. - No uploads. Add
assets_upload_urlandassets_completeif the agent has to bring its own media. - No cancel. Add
jobs_cancelif you want the agent to stop queued jobs. - Re-check the allowlist when you upgrade, since tool ids come from
tools_list.
Measuring the effect
This post has no benchmark for the effect on tokens or latency and does not invent one. To measure it yourself, run the same prompt twice, once with no allowlist and once with the three tools, and compare the token usage reported by the OpenAI API and the wall-clock time to first tool call. Record the date and the number of tools in each run.
Also test a failure: remove jobs_result from the allowlist and confirm the agent stops with a clear message, not a loop. A short tool list should make the agent's options clearer, and the test confirms it.
Sources
Related posts
More in Integrations
- OpenAI remote MCP does not store authorization: resend a Sume key
OpenAI does not store the MCP authorization value, so resend it on every request. Sume accepts a bearer API key or OAuth; keep either one server-side only.
- OpenAI remote MCP does not store authorization: resend your Sume key
OpenAI's remote MCP tool does not keep the authorization value, so every Responses call must carry it. What that means for a Sume key and how to rotate it.
- OpenAI remote MCP is third-party: what a Sume tool call sends
OpenAI says remote MCP servers are third-party services with their own retention. Here is what a Sume tool call carries, and what to keep out of its arguments.
- Pinterest bulk upload: 200 Pins per CSV with Sume media URLs
Pinterest bulk creation takes up to 200 images or videos per upload from a CSV with Title, Media URL and board. Fill the Media URL column from Sume renders.
Written by Sume