readOnlyHint is not authorization: how Sume gates connector tools
A server's readOnlyHint never grants access in Sume. Connector tools need an explicit allowlist, checked when tools are listed and again when a call executes.

Sume does not trust a connected server's readOnlyHint. An annotation is a claim made by the party you are trying to limit. Sume's workspace connectors use an explicit allowlist of tool names and structural input schemas, and it enforces that list twice: when the tool list is built and when a call executes. A hint can only reject a tool, never approve one.
What the docs state
The workspace integrations doc says there is no generic tool-call proxy, URL argument, write operation or prefix-based permission grant, and that readOnlyHint from a server is not authorization. Execution reads the workspace connection again and checks token expiry before it runs anything.
The Meta Ads rules as a concrete case
Sume's reviewed Meta catalog applies three checks. A name alone does not authorize a tool. A positive read-only annotation alone does not authorize it either, because the input schema must match the reviewed structural snapshot. And a negative read-only or destructive annotation rejects a definition. Unknown arguments are rejected on every call.
- Allowed: exact reviewed names whose schemas match the snapshot
- Rejected: anything else, even if it says it is read only
- Rejected: any definition annotated as destructive or not read only
Why two checks
Listing and executing are separate moments. A server could change its catalog between them, or a client could name a tool it never saw. Checking at both points means a stale or forged call fails at execution even if listing was clean. Access also depends on the credential: calls to workspace plugin tools must carry mcp:read.
What to do in your own client
The same principle applies on the client side. If you connect Sume's hosted MCP to a client, you can allowlist only the read tools there as well; see Claude's connector allowlist and the general explainer on readOnlyHint. Treat annotations as UI hints for approval prompts, and use real scopes and allowlists for security.
A simple test for any gateway
Ask three questions of any system that fronts third-party tools. Is there an explicit allowlist of names? Is the input schema compared with a reviewed one? Is the allowlist applied at call time as well as at list time? If any answer is no, a hint is doing a job that only a policy should do.
Sume's connectors answer yes to all three, which is why a connected server can ship new tools without your agents suddenly gaining them.
Related posts
More in Integrations
- Shopify storefront MCP moved to /api/ucp/mcp: update the URL, add Sume
Shopify's storefront MCP now lives at https://{shop}/api/ucp/mcp, not /api/mcp. Update your agent, then add Sume at mcp.sume.com/mcp for product video.
- Shopify UCP needs an agent profile per call: where a Sume clip fits
Shopify's UCP storefront MCP needs an agent profile on every request. A product clip belongs after get_product, as an async Sume job the agent collects later.
- Slack image block with a Sume URL: PNG or JPEG, alt text required
Slack's image block takes a public image_url up to 3000 characters and lists png, jpg, jpeg and gif. Generate a png with Sume, then post it with alt_text.
- Slack connector stopped working after an hour? Reconnect in Sume
When Slack returns no token expiry, Sume assumes one hour. After that an admin must connect again, because v1 has no automatic token renewal for integrations.
Written by Sume