Portkey MCP gateway: per-user tool allowlists for Sume write tools
Portkey's MCP gateway can enable or disable tools per user and log every call. Use it to keep Sume's paid tools from most users, on top of Sume's gates.

An MCP gateway sits between your agents and the servers they call. Portkey's version proxies authentication, access control and logging, per the Portkey MCP gateway page, read 2026-10-03. Clients connect at https://mcp.portkey.ai/{server-slug}/mcp. For a team using Sume's hosted MCP server, the useful part is the page's statement that tools can be enabled or disabled per user.
Two layers of control
Sume enforces its own gates: idempotency_key is required on paid and write tools, and under OAuth the mcp:read scope gives read-only tools while mcp:write is opt-in. The Sume OAuth page says a write or paid tool under mcp:read returns insufficient_scope. A gateway adds a second layer that applies before the request reaches Sume.
| Control | Portkey gateway | Sume |
|---|---|---|
| Who may call a tool | Per-user enable or disable | Credential scope (mcp:read, mcp:write) |
| Audit trail | "Every tool call logged with user, parameters, and response" | Account usage via usage_get |
| Rate limiting | Listed as a gateway feature | 429 with retry-after on the REST API |
| Duplicate protection | Not described on the page | idempotency_key on paid and write tools |
| Spend ceiling | Not described on the page | max_spend_usd when provided |
A sensible split
Give most users the read tools: listing assets, checking jobs_result, reading balance_get. Enable the create tools for a small group that owns generation. The gateway page also lists guardrails and approval workflows; it does not detail them, so check Portkey's docs for how an approval would interrupt a paid call before you rely on it.
Remember that logs contain parameters and responses. A Sume create call carries prompts and an idempotency key, and results can contain asset URLs. Decide who may read the gateway logs the same way you decide who may call the tool.
What the gateway cannot do for you
Treat the gateway as access control and audit, and keep spend control where the job is created. A user allowed to call generate_video should still send a preview first and a cap with the real call.
- It cannot make a retried create safe; only the
idempotency_keydoes that. - It cannot cancel a job that has started generating; Sume returns 409
job_generation_already_startedon late cancels. - It does not replace
max_spend_usdor a cost preview.
Sources
Related posts
More in Integrations
- PrestaShop combination images: one AI image per color
In PrestaShop you upload every image on the product, then tick which ones belong to each combination. Make one image per color from a packshot with Sume.
- Reddit catalog image_link: 500x500 minimum, 20 MB, JPG or PNG
Reddit Ads catalog rules for dynamic product ads: image_link 500x500 or more, 20 MB, JPG or PNG; titles over 35 characters may be cut. Fix photos with Sume.
- Shopify Analytics notes: log each AI video launch with its job id
Shopify Analytics now takes your own notes. Record when an AI product clip went live and its Sume job id, so a later conversion shift has a cause.
- Shopify Events dropped shopify-event-id: build your own Sume job key
Shopify Events deliveries no longer carry shopify-event-id or shopify-resource-id. If you used one as a Sume Idempotency-Key, build a new key from the resource.
Written by Sume