Video generation MCP connector: six questions before you connect

Before you let an agent spend money through any MCP connector, ask six questions. Here are Sume's hosted MCP answers on auth, scopes, idempotency and spend.

4 min readSume
All posts

Before you connect any MCP server that can spend money on video, get answers to six questions: how it authenticates, what a read-only session can see, how repeated calls are deduplicated, what limits spend, how long jobs are held, and how a client discovers the live tool list. Sume's hosted MCP at https://mcp.sume.com/mcp answers each of them in its docs, and the same list works for any other connector.

The checklist with Sume's answers

Use this as a review sheet when you add a connector to a team workspace.

Six connector questions (Sume docs, read 2026-10-07)
QuestionSume hosted MCP
1. How does it authenticate?OAuth (preferred for interactive clients) or an API key sent as a Bearer or x-api-key header
2. What can a read-only session do?OAuth mcp:read shows read-only tools; write and paid tools are hidden and return insufficient_scope
3. How are repeats deduplicated?Write and paid tools require idempotency_key
4. What limits spend?Wallet admission always; optional dry_run preview and optional max_spend_usd that Sume enforces when you provide it
5. How long does one call hold?A hosted call holds at most 55 seconds; use jobs_wait for longer jobs
6. How do I find the live tools?tools_list and tools_schema report the current session, not a fixed list

Details that change your setup

  • There is no mcp:paid scope. Paid calls need mcp:write or an API key, and the wallet is the gate.
  • The Write toggle on the consent page is off by default, so a first connection is read-only.
  • An OAuth token is not a Sume API key. Do not paste either into prompts, and rotate keys that appear in logs.
  • The hosted server does not have full parity with the HTTP API. Sume Image 1.0 and Video 1.0 stay REST-only; the router tools are generate_image and generate_video.

Test it before you trust it

Connect with Write off, call mcp_health and tools_list, and confirm only read tools appear. Then enable write on a throwaway workspace and ask the agent to call tools_schema for the tool you plan to use. Before the first paid call, ask for dry_run=true, and read the estimate, the balance and the queue behavior it returns.

Where a connector is the wrong tool

If a backend creates videos without a person in the loop, call the HTTP API or the Format API directly. MCP is for an agent that decides which tool to call. For fan-out, script_run lets one short program call tools in a loop with max_calls and max_paid_calls limits, which is safer than letting a model call a paid tool fifty times.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume