OpenAI Agents SDK MCP require_approval for Sume write tools
Use require_approval with a tool_names list to gate Sume write tools by name, or connect with OAuth mcp:read so those tools are never visible.

There are two ways to keep Sume write tools from running unattended. Set require_approval on the Agents SDK MCP server so named tools pause for approval, or connect with OAuth mcp:read, where write tools are not shown to the session at all. The first is a pause; the second is hiding.
SDK facts are from OpenAI's MCP page; Sume facts from MCP OAuth and MCP tools and gates, read 2026-09-30.
What forms does require_approval accept?
The page says MCPServerStdio, MCPServerSse and MCPServerStreamableHttp all accept it.
| Form | Effect |
|---|---|
"always" or "never" | Applies to all tools |
True / False | Same as "always" / "never" |
{"delete_file": "always", "read_file": "never"} | Per-tool map |
{"always": {"tool_names": [...]}, "never": {"tool_names": [...]}} | Grouped lists |
What does mcp:read hide on Sume?
Default hosted OAuth grants read only. The OAuth page says mcp:read sessions only see read-only tools, and mcp:write sessions see mutating and paid tools. A write tool called without the scope returns insufficient_scope. An API key gets the full hosted tool set, so with a key the hiding does not apply and approval by name is the control you have.
Which Sume tools would I list?
Examples named in the docs: jobs_cancel and assets_create as write tools, avatars_create and avatar-videos_create as paid. Check the tools list for the full set before writing the tool_names array, since an unlisted tool follows your default.
Does approval replace idempotency_key?
No. idempotency_key is required on write and paid tools regardless, and the docs describe it as transport/dedup, not human approval. dry_run=true gives an admission/cost preview without submitting, which is useful to show the approver. More on pairing the two: tool approval for paid video.
Sources
Related posts
More in Developers
- OpenAI Agents SDK MCPServerManager with a Sume server
Run Sume next to another MCP server in the OpenAI Agents Python SDK: connect Sume over streamable HTTP, check it with mcp_health, and read tools_list.
- OpenAI Batch API limits vs Sume bulk runs: 50,000 vs 100
OpenAI Batch allows 50,000 requests per file with a 24h window. A Sume Format bulk run takes 1-100 items at concurrency 1-16, so chunk your file accordingly.
- OpenAI-compatible /v1/audio/speech: what Sume's TTS route is
Sume has no `/v1/audio/speech` clone. Its TTS is `POST /v1/tts-1.0/generate` or the Router, a job-based request authenticated with a Sume key.
- OpenAI whisper-1 shutdown Feb 2027: a Sume STT alternative
OpenAI removes whisper-1 on Feb 26, 2027. Sume's STT request names no provider model, takes a public audio URL, and caps reserved duration at 10 minutes.
Written by Sume