Grok 4.7 remote MCP tool: connect Sume to the xAI Responses API
xAI's remote MCP tool works with grok-4.7 on the Responses API. Point server_url at Sume's hosted MCP, restrict allowed_tools, and cap spend on the Sume side.

To give Grok 4.7 video generation, send a request to xAI's Responses endpoint with a remote MCP tool whose server_url is https://mcp.sume.com/mcp, a Sume API key in headers, and an allowed_tools list that names only the Sume tools you want. xAI's docs say the remote MCP tool works with grok-4.7.
xAI released Grok 4.7 on Sep 21, 2026, according to its announcement. The model page lists model id grok-4.7, a 500k context, $2 input and $6 output per million tokens, and the endpoint https://api.x.ai/v1/responses. All xAI facts here were read 2026-09-29.
What does xAI's remote MCP tool accept?
The tool object takes the fields below. xAI's page says only streamable HTTP and SSE transports are supported, and that require_approval and connector_id are not supported.
| Field | Purpose |
|---|---|
| type | "mcp" |
| server_url | The remote MCP endpoint |
| server_label | A name for the server |
| allowed_tools | Restrict which tools the model may call |
| authorization | Authorization value for the server |
| headers | Extra request headers |
What is the request?
This uses jq to put the Sume key into the tool's headers, and XAI_API_KEY for xAI. Sume accepts a key as x-api-key or a Bearer token.
curl https://api.x.ai/v1/responses \
-H "Authorization: Bearer $XAI_API_KEY" \
-H "Content-Type: application/json" \
-d "$(jq -n --arg key "$SUME_API_KEY" '{
model: "grok-4.7",
input: "Check Sume MCP health, then list the video tools.",
tools: [{
type: "mcp",
server_url: "https://mcp.sume.com/mcp",
server_label: "sume",
allowed_tools: ["mcp_health", "tools_list"],
headers: { "x-api-key": $key }
}]
}')"Is it safe to hand a key to another vendor?
The key travels to xAI in the request, so treat it as shared with them. Use a key made for this purpose, keep allowed_tools short, and rotate it if it appears in a log. Read-only tools cannot spend; start there, as in the example.
To let the model start a paid clip, add generate_video, jobs_wait and jobs_result. Because xAI does not support require_approval, the approval step has to live on Sume's side.
What replaces the missing approval prompt?
Sume's own arguments. Paid calls need an idempotency_key, dry_run=true previews cost without submitting, and max_spend_usd caps the call when provided. Tell the model in the prompt to preview first and to reuse the same idempotency key on a retry.
Then wait with jobs_wait on the returned job ids. On wait_slice_expired, wait again on the same ids; do not resubmit the create call.
Sources
Related posts
More in Developers
- HeyGen API avatar ID and voice ID: where to find them
In HeyGen's v3 API, avatar_id is a look id from GET /v3/avatars/looks, and voice_id comes from GET /v3/voices or the look's default voice.
- HeyGen API key: get one and make your first video
Generate a HeyGen API key in its API dashboard, send it as X-Api-Key to api.heygen.com, check it with GET /v3/users/me, then create a video.
- HeyGen API v2 retirement: the date and the v3 endpoints
HeyGen's API v1 and v2 stay operational until October 31, 2026 and retire on November 1. The warning headers, and the v3 call for each v2 call.
- How does the Higgsfield API work? Requests, limits, billing
Higgsfield's API is asynchronous: submit to a model endpoint, keep the request_id, poll or take a webhook, download. Billing and limits explained.
Written by Sume