OpenAI Agents SDK MCP require_approval for Sume write tools

Use require_approval with a tool_names list to gate Sume write tools by name, or connect with OAuth mcp:read so those tools are never visible.

4 min readSume
All posts

There are two ways to keep Sume write tools from running unattended. Set require_approval on the Agents SDK MCP server so named tools pause for approval, or connect with OAuth mcp:read, where write tools are not shown to the session at all. The first is a pause; the second is hiding.

SDK facts are from OpenAI's MCP page; Sume facts from MCP OAuth and MCP tools and gates, read 2026-09-30.

What forms does require_approval accept?

The page says MCPServerStdio, MCPServerSse and MCPServerStreamableHttp all accept it.

require_approval forms, from the Agents SDK MCP page read 2026-09-30
FormEffect
"always" or "never"Applies to all tools
True / FalseSame as "always" / "never"
{"delete_file": "always", "read_file": "never"}Per-tool map
{"always": {"tool_names": [...]}, "never": {"tool_names": [...]}}Grouped lists

What does mcp:read hide on Sume?

Default hosted OAuth grants read only. The OAuth page says mcp:read sessions only see read-only tools, and mcp:write sessions see mutating and paid tools. A write tool called without the scope returns insufficient_scope. An API key gets the full hosted tool set, so with a key the hiding does not apply and approval by name is the control you have.

Which Sume tools would I list?

Examples named in the docs: jobs_cancel and assets_create as write tools, avatars_create and avatar-videos_create as paid. Check the tools list for the full set before writing the tool_names array, since an unlisted tool follows your default.

Does approval replace idempotency_key?

No. idempotency_key is required on write and paid tools regardless, and the docs describe it as transport/dedup, not human approval. dry_run=true gives an admission/cost preview without submitting, which is useful to show the approver. More on pairing the two: tool approval for paid video.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume