MCP sub-agent with narrower authority: a read-only Sume token
Give a sub-agent a Sume token granted only mcp:read and it sees read-only tools, so it can inspect jobs and assets but never submit a paid generation.

Connect the sub-agent with an OAuth token that has only mcp:read. Sume's hosted MCP shows such a session read-only tools, so the sub-agent can inspect jobs and assets but cannot see or call a tool that submits work.
The roadmap framing is from the MCP roadmap (last updated 2026-08-22), read 2026-10-01. The scope facts are from MCP OAuth and API keys and MCP tools and gates.
What problem does the roadmap describe?
It describes agents spawning sub-agents that should get narrower authority than their parent, and says servers lean on pasted API keys. A full standard for that is still being worked on. What you can do today is choose the narrowest credential Sume offers.
What does each Sume credential let a sub-agent do?
| Credential | Sees | Mutating call |
|---|---|---|
OAuth mcp:read | Read-only tools | insufficient_scope |
OAuth mcp:read + mcp:write | Mutating and paid tools | Needs idempotency_key |
| API key | Full hosted tool set | Needs idempotency_key |
How do I get a read-only token?
On the consent page, Read is locked on and the Write toggle defaults to off. Leave it off. Supported scopes are mcp:read (required) and mcp:write (opt-in), and granting write always includes read. There is no mcp:paid scope; spend is governed by wallet and admission.
What can a read-only sub-agent still do?
Read tools include jobs_status, jobs_result, jobs_wait, assets_list and generation_admission_preview, so it can check on work the parent started or preview a cost. jobs_cancel is a write tool and is out of reach. If a sub-agent really needs to submit, see the subagent setup and grant write deliberately. One caveat: the token is a bearer token, so keep it out of prompts.
Sources
Related posts
More in Developers
- MCP workload identity federation: Sume takes code grant only
MCP's roadmap names Workload Identity Federation. Sume's hosted MCP advertises only the authorization_code grant, so headless workloads use an API key.
- MCP x-mcp-header and Mcp-Param headers vs Sume idempotency_key
The MCP 2026-07-28 spec can mirror tool parameters into Mcp-Param headers via x-mcp-header. Sume takes idempotency_key as a tool argument in the JSON body.
- Ming Design-Layer splits a design into RGBA layers: Sume does not
Ming-Image-0.1-Design-Layer decomposes a flat design into RGBA PNG layers. Sume's Image API returns finished images, so build layers from transparent elements.
- Ming-Image-0.1-Design on Sume: not in the catalog, use these
Ming-Image-0.1-Design is an open 6B design model. Sume's image catalog does not list it, so send a listed model id such as openai/gpt-image-2.5 for posters.
Written by Sume