Pre-flight tool access: tools_list on Sume's MCP
Notion added a tool that reveals connection-scoped capabilities before requests. Sume's MCP does the same job with tools_list, tools_schema and mcp_health.

Notion's API changelog for September 17, 2026 adds notion-get-tool-access, which returns the full connection-scoped current_tool_access map, showing tool availability by workspace plan and which parameters are restricted. On Sume's hosted MCP the same pre-flight is tools_list, which lists every tool visible in the session with safety metadata, plus tools_schema and mcp_health.
The three discovery tools
The Notion changelog was read on 2026-10-03. Sume's docs list three discovery tools that never spend anything.
| Tool | What it tells you |
|---|---|
| tools_list | Every tool visible in this session, with safety metadata |
| tools_schema | One tool's contract, fetched by name |
| mcp_health | Endpoint readiness, auth source and safety posture |
Visibility depends on scope
Hosted MCP defaults to read-only visibility under OAuth mcp:read. Mutating and paid tools are hidden until the session has mcp:write or uses an API key. If a call to a mutating tool is made without write scope it returns insufficient_scope. There is no mcp:paid scope; spend is governed by the wallet and admission.
So the answer to what this connection can do is read directly from tools_list rather than guessed from the tool inventory in the docs.
| Session auth | What you see and can call |
|---|---|
| OAuth mcp:read only | Read-only tools; mutating or paid calls return insufficient_scope |
| OAuth mcp:read and mcp:write | Full hosted tool set |
| API key | Full hosted tool set |
A pre-flight routine
Ask the agent to run this sequence before any paid work.
- Call
mcp_healthand confirmauthenticated.auth_source; the docs expectmcp_oauthfor an OAuth session. - Call
tools_listand note which tools are read-only. - Call
tools_schemawithname: "generate_image"and readidempotency_keyanddry_runbefore any submit. - Call
generation_admission_previewor send the paid tool withdry_run=trueto see estimate, balance and queue behavior.
Do not assume parity with the API
The docs say to discover the live contract with tools_list and tools_schema and not to assume HTTP API parity. catalog_list can show HTTP capabilities that have no matching MCP tool. Treat tools_list as the authority for what an agent can call in this session.
Sources
Related posts
More in Developers
- Push or poll for a finished render: listen, webhook or jobs_wait
MCP 2026-07-28 adds subscriptions/listen. For a render that takes minutes, compare a listen stream, a signed webhook and jobs_wait, with a Python verifier.
- Pydantic AI slot leak vs Sume queue_full: tell them apart
Pydantic AI v2.53.0 fixed a streamed-request concurrency slot leak. A client limiter is not Sume's workspace queue_full 429, and each needs its own handling.
- Pydantic AI Workspace sandboxes: fetch Sume artifacts
Pydantic AI's Workspace abstraction runs tools locally or in sandboxes. Inside a sandbox, fetch Sume artifact URLs, and give Sume inputs as public HTTPS URLs.
- Python 3.10 is end of life: a stdlib Sume webhook verifier
Python 3.10 has reached end of life. A standard-library verifier for Sume's signed webhooks that refuses an empty secret and accepts rotated signatures.
Written by Sume