Sume MCP with an API key versus OAuth: which tools your AI client sees

Why Claude, Cursor, Codex or Copilot may show fewer Sume tools: OAuth is read-only until consent includes write; an API key shows all.

5 min readSume
All posts

If a client lists fewer Sume tools than you expected, check how it authenticated. An OAuth session starts read-only (mcp:read) and gains write tools only if the user turned on mcp:write at consent. An API key sent as Authorization: Bearer or x-api-key returns the full tool set and spends against that key's workspace.

Start diagnosis with the discovery tools: mcp_health, tools_list, tools_schema, catalog_list, account_me and generation_admission_preview.

Symptoms and fixes

MCP access symptoms per Sume docs (read 2026-10-03)
SymptomLikely causeFix
Paid tools missingOAuth without mcp:writeRe-consent with Write on
insufficient_scope on generateRead-only OAuth sessionRe-consent with Write on, or use a key
Tool list differs between clientsDifferent credentialsCompare account_me output
Image 1.0 or Video 1.0 not listedREST-onlyCall images_create or videos_create over REST

Preview before paying

generation_admission_preview and dry_run let a client check admission and cost without submitting, and max_spend_usd caps a call when sent. They are arguments the model writes, so they are guidance, not a limit your client enforces.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume