Pre-flight tool access: tools_list on Sume's MCP

Notion added a tool that reveals connection-scoped capabilities before requests. Sume's MCP does the same job with tools_list, tools_schema and mcp_health.

4 min readSume
All posts

Notion's API changelog for September 17, 2026 adds notion-get-tool-access, which returns the full connection-scoped current_tool_access map, showing tool availability by workspace plan and which parameters are restricted. On Sume's hosted MCP the same pre-flight is tools_list, which lists every tool visible in the session with safety metadata, plus tools_schema and mcp_health.

The three discovery tools

The Notion changelog was read on 2026-10-03. Sume's docs list three discovery tools that never spend anything.

Sume MCP discovery tools (read 2026-10-03)
ToolWhat it tells you
tools_listEvery tool visible in this session, with safety metadata
tools_schemaOne tool's contract, fetched by name
mcp_healthEndpoint readiness, auth source and safety posture

Visibility depends on scope

Hosted MCP defaults to read-only visibility under OAuth mcp:read. Mutating and paid tools are hidden until the session has mcp:write or uses an API key. If a call to a mutating tool is made without write scope it returns insufficient_scope. There is no mcp:paid scope; spend is governed by the wallet and admission.

So the answer to what this connection can do is read directly from tools_list rather than guessed from the tool inventory in the docs.

Session auth and what it exposes (read 2026-10-03)
Session authWhat you see and can call
OAuth mcp:read onlyRead-only tools; mutating or paid calls return insufficient_scope
OAuth mcp:read and mcp:writeFull hosted tool set
API keyFull hosted tool set

A pre-flight routine

Ask the agent to run this sequence before any paid work.

  • Call mcp_health and confirm authenticated.auth_source; the docs expect mcp_oauth for an OAuth session.
  • Call tools_list and note which tools are read-only.
  • Call tools_schema with name: "generate_image" and read idempotency_key and dry_run before any submit.
  • Call generation_admission_preview or send the paid tool with dry_run=true to see estimate, balance and queue behavior.

Do not assume parity with the API

The docs say to discover the live contract with tools_list and tools_schema and not to assume HTTP API parity. catalog_list can show HTTP capabilities that have no matching MCP tool. Treat tools_list as the authority for what an agent can call in this session.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume