stt_create in a read-only MCP session: insufficient_scope, not a bug
A read-only OAuth session on Sume's MCP server can list tools but paid calls such as stt_create and tts_create return insufficient_scope. What to switch on.

If stt_create or tts_create fails with insufficient_scope over Sume's MCP server, your session probably has only mcp:read. Sume's MCP tools and gates docs, read 2026-10-03, say an OAuth session with mcp:read only gets read-only tools and that mutating or paid calls return insufficient_scope. Sign in again with mcp:write granted, or use an API key, which sees the full hosted tool set.
Which session can call what?
The docs list music_create, tts_create and stt_create among the paid tools, so all three need write scope.
| Session | What it can call |
|---|---|
OAuth mcp:read only | Read-only tools; paid and write calls return insufficient_scope |
OAuth mcp:read + mcp:write | Full hosted tool set; paid calls still need idempotency_key |
| API key | Full hosted tool set; same idempotency_key rules |
What still works in a read-only session?
Reads that are free: tts_source_get, a manifest of the accepted script for a tts_create with transcript_source, and tts_source_verify_spine, which checks selected TTS jobs against that script. Job reads such as status and results are read tools as well. That means a read-only session can audit narration already generated, even though it cannot create more.
What do I check before changing scopes?
- Confirm the client really requested
mcp:write; some clients ask for read only by default, and consent screens may leave the write toggle off. - Preview before you spend:
dry_run=truereturns an admission and cost preview without submitting the job. max_spend_usdis enforced only when you send it, so a session with write scope can still spend whatever the model asks for.
Sources
Related posts
More in Integrations
- Sume hosted MCP OAuth scopes: mcp:read, mcp:write, and no paid scope
What a client gets after OAuth consent on https://mcp.sume.com/mcp: mcp:read always, mcp:write opt-in, and an API key for the full tool set.
- Sume MCP with an API key versus OAuth: which tools your AI client sees
Why Claude, Cursor, Codex or Copilot may show fewer Sume tools: OAuth is read-only until consent includes write; an API key shows all.
- Sume MCP script_run: timeout 5 to 55 seconds, max_paid_calls brake
script_run in the hosted Sume MCP runs JavaScript with sume.call, a 5 to 55 second timeout and call limits, and journals every call and job it started.
- Theia AI MCP oauth block and ~{mcp_} tool syntax with Sume tools
Theia AI can sign in to a remote MCP server with an oauth block and call its tools as ~{mcp_server_tool}. Here is how that maps to Sume's jobs_wait and gates.
Written by Sume