stt_create in a read-only MCP session: insufficient_scope, not a bug

A read-only OAuth session on Sume's MCP server can list tools but paid calls such as stt_create and tts_create return insufficient_scope. What to switch on.

4 min readSume
All posts

If stt_create or tts_create fails with insufficient_scope over Sume's MCP server, your session probably has only mcp:read. Sume's MCP tools and gates docs, read 2026-10-03, say an OAuth session with mcp:read only gets read-only tools and that mutating or paid calls return insufficient_scope. Sign in again with mcp:write granted, or use an API key, which sees the full hosted tool set.

Which session can call what?

The docs list music_create, tts_create and stt_create among the paid tools, so all three need write scope.

Session auth rules from the Sume MCP docs, read 2026-10-03
SessionWhat it can call
OAuth mcp:read onlyRead-only tools; paid and write calls return insufficient_scope
OAuth mcp:read + mcp:writeFull hosted tool set; paid calls still need idempotency_key
API keyFull hosted tool set; same idempotency_key rules

What still works in a read-only session?

Reads that are free: tts_source_get, a manifest of the accepted script for a tts_create with transcript_source, and tts_source_verify_spine, which checks selected TTS jobs against that script. Job reads such as status and results are read tools as well. That means a read-only session can audit narration already generated, even though it cannot create more.

What do I check before changing scopes?

  • Confirm the client really requested mcp:write; some clients ask for read only by default, and consent screens may leave the write toggle off.
  • Preview before you spend: dry_run=true returns an admission and cost preview without submitting the job.
  • max_spend_usd is enforced only when you send it, so a session with write scope can still spend whatever the model asks for.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume