readOnlyHint is not authorization: how Sume gates connector tools

A server's readOnlyHint never grants access in Sume. Connector tools need an explicit allowlist, checked when tools are listed and again when a call executes.

5 min readSume
All posts

Sume does not trust a connected server's readOnlyHint. An annotation is a claim made by the party you are trying to limit. Sume's workspace connectors use an explicit allowlist of tool names and structural input schemas, and it enforces that list twice: when the tool list is built and when a call executes. A hint can only reject a tool, never approve one.

What the docs state

The workspace integrations doc says there is no generic tool-call proxy, URL argument, write operation or prefix-based permission grant, and that readOnlyHint from a server is not authorization. Execution reads the workspace connection again and checks token expiry before it runs anything.

The Meta Ads rules as a concrete case

Sume's reviewed Meta catalog applies three checks. A name alone does not authorize a tool. A positive read-only annotation alone does not authorize it either, because the input schema must match the reviewed structural snapshot. And a negative read-only or destructive annotation rejects a definition. Unknown arguments are rejected on every call.

  • Allowed: exact reviewed names whose schemas match the snapshot
  • Rejected: anything else, even if it says it is read only
  • Rejected: any definition annotated as destructive or not read only

Why two checks

Listing and executing are separate moments. A server could change its catalog between them, or a client could name a tool it never saw. Checking at both points means a stale or forged call fails at execution even if listing was clean. Access also depends on the credential: calls to workspace plugin tools must carry mcp:read.

What to do in your own client

The same principle applies on the client side. If you connect Sume's hosted MCP to a client, you can allowlist only the read tools there as well; see Claude's connector allowlist and the general explainer on readOnlyHint. Treat annotations as UI hints for approval prompts, and use real scopes and allowlists for security.

A simple test for any gateway

Ask three questions of any system that fronts third-party tools. Is there an explicit allowlist of names? Is the input schema compared with a reviewed one? Is the allowlist applied at call time as well as at list time? If any answer is no, a hint is doing a job that only a policy should do.

Sume's connectors answer yes to all three, which is why a connected server can ship new tools without your agents suddenly gaining them.

Related posts

More in Integrations

All Integrations posts

Written by Sume