n8n MCP workflow access error vs a Sume insufficient_scope
n8n now links MCP workflow access errors to workflow settings. A Sume failure reads differently: insufficient_scope means the OAuth session lacks mcp:write.

If the error links to a workflow's settings, it came from n8n's side; if it names insufficient_scope, it came from Sume and means the session has read access but you called a write or paid tool. The fix for the second is to grant mcp:write on consent or use an API key, not to change anything in n8n.
The n8n line is from its release notes; the Sume behavior is from MCP OAuth and API keys and the MCP quickstart, read 2026-09-30.
What did n8n change?
The n8n 2.42.0 release notes list under core: "Link MCP workflow access errors to workflow settings" (issue 39738). The notes give no more detail, so check n8n's own docs for which workflow setting controls access.
How do I tell which side failed?
| Symptom | Likely side | What to check |
|---|---|---|
| Message points to workflow settings | n8n | The workflow's MCP access setting in n8n |
insufficient_scope on a create or cancel tool | Sume | Session has mcp:read only; needs mcp:write or an API key |
Read tools such as jobs_list work, writes fail | Sume | Same cause: read-only session |
What does a read-only Sume session see?
Under OAuth the default is mcp:read, and those sessions only see read-only tools. The quickstart says tools such as jobs_cancel or assets_create return insufficient_scope, and so do paid tools such as generate_image. There is no mcp:paid scope; spend is wallet and admission based.
How do I get write access?
Turn on the Write toggle on the consent page (it defaults to off), or send an API key as Authorization: Bearer <SUME_API_KEY> or x-api-key, which gives the full hosted tool set. For Claude Code the quickstart's connect line is claude mcp add --transport http sume https://mcp.sume.com/mcp. After that, write and paid tools need an idempotency_key. See MCP insufficient_scope troubleshooting.
Sources
Related posts
More in Integrations
- n8n nested AI agent tool: one idempotency_key per Sume generation
n8n's AI Agent Tool can now use its own tools under a pre-v3 parent agent. If both levels reach a Sume paid tool, reuse one idempotency_key per generation.
- Notion 504 gateway_timeout: check the page before you retry
A Notion 504 gateway_timeout does not mean the write was undone. Read the page, write the Sume video URL once, and dedupe on the webhook's job_id.
- opencode mcp auth: sign in to Sume, list, debug, log out
Run opencode mcp auth sume to start Sume's OAuth consent, then list, debug or logout. v1.18.33 now reports browser launch failures and redacts debug output.
- Pinterest MCP with Claude: make the 2:3 pin with Sume
Pinterest MCP reads campaign and keyword data for an agent. Pair it with Sume's hosted MCP to generate the 2:3 pin image in the same Claude session.
Written by Sume