OpenAI remote MCP is third-party: what a Sume tool call sends
OpenAI says remote MCP servers are third-party services with their own retention. Here is what a Sume tool call carries, and what to keep out of its arguments.

A Sume tool call sends its arguments to Sume, and nothing else from your conversation, so keep sensitive text out of those arguments. OpenAI's remote MCP guide calls remote servers third-party services that OpenAI has not verified, and says data sent to them follows their retention policies, not necessarily your organization's (read 2026-10-05). By default, the guide says the system requests your approval before data is shared.
What actually leaves your process
When the model calls generate_image or tts_create, the call carries the tool arguments: a prompt or script, an idempotency_key, and optional dry_run and max_spend_usd gates. Hosted MCP cannot read files from a laptop, so media reaches Sume through URLs or an upload flow, not through your disk.
Sume's docs mark what is safe to log: request ids, job ids when necessary, high-level status and sanitized media metadata. They mark API keys, signed URLs, raw private media URLs and large amounts of user content or transcripts as unsafe.
| Data | In a Sume tool call? | Log it? |
|---|---|---|
| Prompt or script text | Yes, as an argument | Only a short, non-sensitive excerpt |
| idempotency_key | Yes, required on paid calls | Yes, it is a stable id |
| API key or OAuth token | In the auth header, not in arguments | Never |
| Signed media URLs | Only if you pass one | Never |
| Sume request_id and job id | In the response | Yes |
Two layers of consent
The OpenAI default approval step is the first layer: a person or policy decides whether the call may go out. Sume's own gates are the second. Paid and write tools need idempotency_key, and under OAuth mcp:read they are hidden or return insufficient_scope until mcp:write is granted. There is no mcp:paid scope; spend is decided by the wallet and admission.
Redact before you log an approval request
An mcp_approval_request item carries arguments as a JSON string. This helper parses it, masks any key that looks like a credential, and truncates long text, so the line is safe to store. It runs offline.
import json
SECRET_HINTS = ("key", "token", "secret", "authorization", "url")
def redact(arguments_json: str, limit: int = 40) -> dict:
args = json.loads(arguments_json)
safe = {}
for name, value in args.items():
if any(h in name.lower() for h in SECRET_HINTS):
safe[name] = "***"
elif isinstance(value, str) and len(value) > limit:
safe[name] = value[:limit] + "..."
else:
safe[name] = value
return safe
if __name__ == "__main__":
raw = '{"prompt": "A long product brief that may hold names", "idempotency_key": "k1"}'
print(redact(raw))Rate limits are a separate concern
The same guide notes that remote MCP calls count against rate limits, with Tier 1 at 200 requests per minute and higher tiers up to 2,000 (read 2026-10-05). That is a limit on how often your agent can reach any remote server, Sume included, and it has nothing to do with data handling.
It does shape design, though. A tool that sends one large, well-formed call is cheaper in requests than five small ones, and for several media jobs a single batch wait is better than many status polls.
Policy to adopt
Write down what may go into a prompt that crosses to a third party, and enforce it before the tool call.
- Strip personal data from prompts that go to media tools.
- Pass untrusted text as data, not as instructions.
- Store ids and statuses, and fetch media by id when you need it.
- Review the retention terms of every remote MCP server you attach, including Sume's.
Sources
Related posts
More in Integrations
- Pinterest bulk upload: 200 Pins per CSV with Sume media URLs
Pinterest bulk creation takes up to 200 images or videos per upload from a CSV with Title, Media URL and board. Fill the Media URL column from Sume renders.
- Pub/Sub push ack codes and a Sume webhook relay with a signature check
Pub/Sub treats only 102, 200, 201, 202 and 204 as acks. Verify Sume's sume-v1 signature at the edge, publish, return 2xx, and let Pub/Sub retry the workers.
- Shopify storefront MCP moved to /api/ucp/mcp: update the URL, add Sume
Shopify's storefront MCP now lives at https://{shop}/api/ucp/mcp, not /api/mcp. Update your agent, then add Sume at mcp.sume.com/mcp for product video.
- Shopify UCP needs an agent profile per call: where a Sume clip fits
Shopify's UCP storefront MCP needs an agent profile on every request. A product clip belongs after get_product, as an async Sume job the agent collects later.
Written by Sume