require_approval never with tool_names for Sume read tools
Use the object form of require_approval to skip approval only for Sume read tools like account_me, and keep every paid tool on the approval path.

OpenAI's require_approval accepts always, never, or an object such as {"never":{"tool_names":[...]}}. For Sume, list the read tools in the never object, namely mcp_health, tools_list, tools_schema, account_me and catalog_list, so everything else is not exempted.
The syntax comes from OpenAI's MCP guide. The tool names come from Sume's hosted MCP docs, which call these the discovery tools.
Approval round trip
When approval is needed, the response contains an mcp_approval_request output item. You answer with an mcp_approval_response input item that carries approve and approval_request_id. Show the user the tool name and arguments before you approve a paid call.
| Piece | Where it appears | Purpose |
|---|---|---|
mcp_approval_request | Output item | Asks your app to approve one tool call |
mcp_approval_response | Input item | Carries approve and approval_request_id |
require_approval object | Tool config | Names tools that never need approval |
allowed_tools | Tool config | Limits what the model can call |
Config for Sume
{
"type": "mcp",
"server_label": "sume",
"server_url": "https://mcp.sume.com/mcp",
"authorization": "<SUME_OAUTH_TOKEN>",
"require_approval": {
"never": {
"tool_names": ["mcp_health", "tools_list", "tools_schema", "account_me", "catalog_list"]
}
}
}Why not set never for everything
A paid Sume tool spends credits. It needs an idempotency_key and may carry max_spend_usd (tools and gates), but the model chooses the values. An approval step lets a person see the estimate from dry_run before the money moves. A read-only OAuth token adds a second guard, since write and paid tools are hidden under mcp:read.
Sources
Related posts
More in Developers
- Restyle burned-in captions without transcribing twice
Pass source_caption_id instead of video_url to re-burn a video under a new Sume caption style. Word timings are reused, so no second speech-to-text runs.
- Resume an Omni batch after a crash with stable idempotency keys
A worker dies halfway through 40 Omni clips. Build Idempotency-Key from the item id so a rerun resubmits safely, and treat 409 and 429 as signals, not failures.
- Retrain a cloned voice without breaking old videos
HeyGen keeps a voice ID when a clone is retrained. On Sume, an avatar is referenced by a stable handle, and each text-to-speech job records its voice and model.
- Retry a failed image batch on Sume: not billed, same Idempotency-Key
On Sume a failed image generation is not billed, but a retry after a timeout can double-submit. Send an Idempotency-Key per image and retry only the submit.
Written by Sume