HeyGen videos:write and videos:read vs Sume scopes mcp:read/write

HeyGen needs videos:write to create and videos:read to poll. Hosted Sume OAuth has mcp:read and mcp:write, no paid scope; spend is wallet admission.

4 min readSume
All posts

HeyGen's heygen-video-1 creation needs an API key with videos:write, and polling needs videos:read. Sume's hosted MCP OAuth has two scopes: mcp:read (required) and mcp:write (opt-in). There is no mcp:paid scope; paid submits go through wallet admission.

HeyGen facts are from its API changelog; Sume facts from MCP OAuth and MCP tools and gates, read 2026-10-01.

How does HeyGen split create and poll?

Per the changelog, API keys need videos:write to create and videos:read to poll, and you send an idempotency header on submit so a retry does not start a second generation.

How do Sume's scopes compare?

Session behavior from the Sume docs, read 2026-10-01.
SessionWhat it can do
OAuth mcp:read onlyRead-only tools; mutating or paid calls return insufficient_scope
OAuth mcp:read + mcp:writeFull hosted tool set
API keyFull hosted tool set

Is there a paid scope?

No. The docs say paid submits are wallet and admission, not a scope. Mutating and paid tools are hidden until the session has mcp:write or an API key, and write or paid tools require an idempotency_key. Granting write always includes read.

Which setup fits a polling-only client?

Grant only mcp:read to a client that reads job state, and add mcp:write where something creates jobs. Preview spend with dry_run and cap it with max_spend_usd, which is enforced only when provided. See API keys vs OAuth for MCP.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume