Which MCP grant lets an agent create an avatar? Write, no paid scope

On Sume's hosted MCP, avatars_create and the avatar video tools are paid tools that need the Write toggle at consent. There is no mcp:paid scope.

5 min readSume
All posts

To let an agent create an avatar through Sume's hosted MCP, grant mcp:write on the consent page. The avatar creation tool, avatars_create, is listed as a paid tool, and there is no separate mcp:paid scope (as of 2026-10-09). With read-only access, the agent can list and read avatars but cannot spend.

Which avatar tools sit on which side

The MCP tools page splits avatar tools into read and paid. The agent sees read tools with mcp:read, and the paid ones only after you opt in to write.

Avatar and talking-head tools on the MCP tools page, as of 2026-10-09
GroupTools
Readavatars_list, avatars_get, avatars_search, avatar-videos_list, avatar-videos_get
Paidavatars_create, avatar-videos_create, avatar-image-to-video_create
Paid (preview flow)avatar-video-previews_create, _get, _regenerate, _generate_video
Paid (separate family)kling-motion-control_create

OAuth versus an API key

With OAuth, the client sends you to the MCP host consent page, where Read is locked on and Write is off by default. The docs say mcp:read is required and that there is no mcp:paid scope. An API key gives the full hosted tool set, with spend governed by the wallet and admission, as the OAuth page describes. Either way, writes and paid calls must include an idempotency_key, so give each avatar its own key and reuse that key if you retry the call.

What a read-only agent can still do

A read-only agent can list your avatars and read their status, and it can read avatar videos, so it can answer a question like which handles are ready and which videos were made last week. It cannot call avatars_create or the render tools. That split suits a reporting agent with no budget.

If you later enable write, set a budget in your own instructions: no more than one avatar per run and no render above 15 seconds at plus, which is 15 x 0.245 = $3.675. The wallet and admission still decide whether a call can run.

A safe rollout

Start an agent on read only and let it call avatars_list so you can see its view of your handles. Move to write when you have a budget and a prompt that names the handle. The cost for a new avatar is $0.95; a 10-second talking video from it is 10 x $0.184 = $1.84 at standard, so one agent run that creates an avatar and one video is $2.79 at standard.

If your client does not support the OAuth consent page, an API key is the other way to reach the hosted tools. Keep the key out of chat logs and rotate it if it leaks.

Last, remember the cost of a mistake: an avatar created by a misread instruction is $0.95, and a render at max for 30 seconds is 30 x 0.55 = $16.50. Set the instruction so that the agent asks before any max-tier render.

  • Ask the agent to report the handle before it renders.
  • Prefer previews for videos over 20 seconds.
  • Review the job id list at the end of a run.

Sources

Related posts

More in Sume Avatar 1.0

All Sume Avatar 1.0 posts

Written by Sume