OpenAI remote MCP is third-party: what a Sume tool call sends

OpenAI says remote MCP servers are third-party services with their own retention. Here is what a Sume tool call carries, and what to keep out of its arguments.

5 min readSume
All posts

A Sume tool call sends its arguments to Sume, and nothing else from your conversation, so keep sensitive text out of those arguments. OpenAI's remote MCP guide calls remote servers third-party services that OpenAI has not verified, and says data sent to them follows their retention policies, not necessarily your organization's (read 2026-10-05). By default, the guide says the system requests your approval before data is shared.

What actually leaves your process

When the model calls generate_image or tts_create, the call carries the tool arguments: a prompt or script, an idempotency_key, and optional dry_run and max_spend_usd gates. Hosted MCP cannot read files from a laptop, so media reaches Sume through URLs or an upload flow, not through your disk.

Sume's docs mark what is safe to log: request ids, job ids when necessary, high-level status and sanitized media metadata. They mark API keys, signed URLs, raw private media URLs and large amounts of user content or transcripts as unsafe.

Third-party tool call data handling, read 2026-10-05
DataIn a Sume tool call?Log it?
Prompt or script textYes, as an argumentOnly a short, non-sensitive excerpt
idempotency_keyYes, required on paid callsYes, it is a stable id
API key or OAuth tokenIn the auth header, not in argumentsNever
Signed media URLsOnly if you pass oneNever
Sume request_id and job idIn the responseYes

Two layers of consent

The OpenAI default approval step is the first layer: a person or policy decides whether the call may go out. Sume's own gates are the second. Paid and write tools need idempotency_key, and under OAuth mcp:read they are hidden or return insufficient_scope until mcp:write is granted. There is no mcp:paid scope; spend is decided by the wallet and admission.

Redact before you log an approval request

An mcp_approval_request item carries arguments as a JSON string. This helper parses it, masks any key that looks like a credential, and truncates long text, so the line is safe to store. It runs offline.

import json

SECRET_HINTS = ("key", "token", "secret", "authorization", "url")

def redact(arguments_json: str, limit: int = 40) -> dict:
    args = json.loads(arguments_json)
    safe = {}
    for name, value in args.items():
        if any(h in name.lower() for h in SECRET_HINTS):
            safe[name] = "***"
        elif isinstance(value, str) and len(value) > limit:
            safe[name] = value[:limit] + "..."
        else:
            safe[name] = value
    return safe

if __name__ == "__main__":
    raw = '{"prompt": "A long product brief that may hold names", "idempotency_key": "k1"}'
    print(redact(raw))

Rate limits are a separate concern

The same guide notes that remote MCP calls count against rate limits, with Tier 1 at 200 requests per minute and higher tiers up to 2,000 (read 2026-10-05). That is a limit on how often your agent can reach any remote server, Sume included, and it has nothing to do with data handling.

It does shape design, though. A tool that sends one large, well-formed call is cheaper in requests than five small ones, and for several media jobs a single batch wait is better than many status polls.

Policy to adopt

Write down what may go into a prompt that crosses to a third party, and enforce it before the tool call.

  • Strip personal data from prompts that go to media tools.
  • Pass untrusted text as data, not as instructions.
  • Store ids and statuses, and fetch media by id when you need it.
  • Review the retention terms of every remote MCP server you attach, including Sume's.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume