Connected-app tools in Sume: plugin prefixes and the mcp:read rule

Tools from a connected app get a provider namespace such as slack_plugin_ or meta_plugin_, need mcp:read, and a plugin outage does not break unrelated tools.

5 min readSume
All posts

Tools that come from a connected app are namespaced by provider in Sume's agent MCP. The docs list prefixes such as meta_plugin_, slack_plugin_, gmail_plugin_, google_drive_plugin_, google_docs_plugin_ and google_sheets_plugin_. A call to any of them needs mcp:read, and a plugin outage does not break discovery of unrelated agent tools.

Where this applies

The doc describes the authenticated studio-agent MCP tools/list and tools/call, which use the workspace id of the session. That is the surface Sume's own agents use inside a workspace. It is not the public hosted MCP at https://mcp.sume.com/mcp that you add to Claude, Cursor or Codex; that server exposes Sume's generation tools. See which URL to configure if you mixed them up.

What the prefix buys

  • Collision safety: two providers cannot define the same tool name
  • Auditability: a call names the provider it touched
  • Per-provider gating: coming-soon providers are removed from listing and execution through the same availability gate

Scopes

mcp:read is the required scope for these calls. The connectors are read-only by design, so there is no write scope story for them. Sume's hosted MCP scopes are mcp:read (required) and mcp:write (opt-in); the plugin tools only ever need the read one.

Isolation

Plugin tools resolve the workspace connection from the session workspace. Another workspace gets no tools and no credentials from your connection, and disconnecting removes the tool availability for the workspace that disconnected.

Debugging

If an agent cannot see a plugin tool, check three things in order: is the provider live and connected on the Integrations page, has the token expired and needs a reconnect, and does the session credential carry mcp:read. For credential questions on the hosted MCP, mcp_health reports which auth source and scopes a session is using.

Why not one flat tool list

A flat list would let the first connected provider claim a name like search and hide others. Namespacing by provider also makes the allowlist easy to audit: each prefix has its own reviewed set, and Sume can turn a provider off without touching the rest.

As new providers go live, expect new prefixes, not changes to the old ones.

Related posts

More in Integrations

All Integrations posts

Written by Sume