Tavus MCP server and CLI vs Sume hosted MCP: auth and spend caps
Tavus MCP uses browser OAuth plus a tavus CLI; Sume hosted MCP has read-only OAuth, opt-in write, API keys, idempotency_key, dry_run and max_spend_usd.

Both vendors let an editor agent drive the API. Tavus offers an MCP server at https://mcp.tavus.io/mcp and a tavus CLI; Sume offers a hosted MCP at https://mcp.sume.com/mcp. The difference buyers feel is spend control: Sume's MCP requires an idempotency_key on paid calls and offers dry_run and max_spend_usd to preview and cap cost.
Tavus's pages describe building PALs, defining tools and testing integrations, which is a build-time workflow. Sume's MCP is for generating media as well as managing it.
What Tavus documents
Tavus says its MCP server connects Codex, Claude Code, Cursor or any MCP client over HTTPS, with browser-based OAuth through PAL Maker and per-user keys forwarded as an x-api-key header. The CLI authenticates with tavus auth login, which stores environment-scoped keys in the OS keychain, or with TAVUS_API_KEY for automation, and both surfaces call the same API. The default environment is production; TAVUS_ENV=TEST targets the test database (Tavus docs: Agent Tools).
What Sume's hosted MCP does
Sume's hosted MCP accepts OAuth access tokens or Sume API keys. Under OAuth, mcp:read is required and read-only; the user can toggle Write at consent to also grant mcp:write. There is no mcp:paid scope: paid submits go through wallet and admission. With an API key you get the full hosted tool set (MCP OAuth and API keys).
On write and paid tools idempotency_key is required as a dedupe key, not as approval. dry_run=true previews admission and cost without submitting, and max_spend_usd is enforced only when you pass it (MCP tools and gates).
| Control | Tavus MCP and CLI | Sume hosted MCP |
|---|---|---|
| Interactive login | Browser OAuth via PAL Maker | OAuth with mcp:read, optional mcp:write |
| Automation | TAVUS_API_KEY, tavus auth login | API key as Bearer or x-api-key |
| Cost preview | Not described on the page | dry_run=true |
| Spend cap per call | Not described on the page | max_spend_usd when provided |
| Duplicate protection | Not described on the page | idempotency_key required on writes and paid |
Which to connect
For building a live agent, connect Tavus. For generating clips from an editor while keeping a spend ceiling, connect Sume, start with read-only OAuth, and give an agent a max_spend_usd on every paid call.
- An MCP OAuth token is not an API key. Do not mint a key to work around a missing scope.
- Rotate any API key that appears in logs or chat.
A safe starting setup
Start the Sume connection with OAuth and read-only scope so the agent can list models and read results but cannot spend. Add write consent only when a task needs it, and instruct the agent to call with dry_run=true first and show the cost.
For unattended automation use an API key held in an environment variable, a max_spend_usd on every paid call, and a stable idempotency_key per intended job. A retry with the same key does not create a second job.
What to test first
Connect each server from your editor and run one read-only call. On Sume, list the available tools and ask for the schema of one generation tool before calling it. Then run that tool with dry_run=true and read the cost it returns.
Only then allow a paid call, with a max_spend_usd that you are comfortable losing if the result is wrong.
Sources
Related posts
More in Integrations
- Theia AI MCP oauth block and ~{mcp_} tool syntax with Sume tools
Theia AI can sign in to a remote MCP server with an oauth block and call its tools as ~{mcp_server_tool}. Here is how that maps to Sume's jobs_wait and gates.
- Theia AI remote MCP server: serverUrl and serverAuthToken for Sume
Theia AI's remote MCP config takes serverUrl, serverAuthToken and an optional serverAuthTokenHeader. The entry for Sume's hosted MCP with a Bearer API key.
- TikTok catalog feed: image hosts TikTok lists, and where Sume URLs fit
TikTok's catalog page names supported and unsupported image hosts and asks for 720x1280 video. How to prepare a video_link clip with Sume trim.
- QStash to Sume: forward headers, 3 default retries, pinned key
QStash can publish straight to api.sume.com with Upstash-Forward headers and retries 3 times. Pin an Idempotency-Key; the API key sits in the stored message.
Written by Sume