AgentCore payments GA vs Sume's API key and credit balance
AWS made AgentCore payments GA on Aug 18, 2026 with x402 upto and MPP. Sume uses an API key or OAuth with a credit balance and per-call spend caps instead.

AWS announced general availability of Amazon Bedrock AgentCore payments on August 18, 2026. It supports x402, including the upto scheme, and the Machine Payment Protocol (MPP), with Coinbase and Stripe Privy wallets. Sume takes a different path: you authenticate with an API key or OAuth token and a credit balance pays, with limits set per call.
Both approaches answer the same question, which is how to stop an agent from overspending. The AWS announcement says payment limits are enforced at the infrastructure layer. Sume enforces them in the request and at admission.
What AWS announced and what Sume offers
| Topic | AgentCore payments | Sume |
|---|---|---|
| Protocols | x402 with upto, and MPP | Plain HTTPS with API key or OAuth |
| Wallets | Coinbase and Stripe Privy | Account credit balance |
| Limits | Enforced at the infrastructure layer | max_spend_usd per MCP call; required generation_spend_cap_usd on Agent Completions |
| Catalog | Curated Coinbase Bazaar MCP server via the AgentCore gateway | Sume's own hosted MCP at https://mcp.sume.com/mcp |
| Insufficient funds | Payment is declined | 402 insufficient_credits |
Can an AgentCore agent call Sume?
Sume's hosted MCP is an ordinary remote HTTPS server, so any agent platform that can attach a header or an OAuth token can reach it. The AWS page does not say Sume is a catalog entry, and this post does not claim it is. If you route through a gateway, give it an API key with only the scopes the job needs, and do not expect wallet-signed payments to reach Sume.
What you gain is a single predictable ceiling. A paid call carries an idempotency_key, and a dry_run shows the estimate first (tools and gates).
Choosing between them
- Pay-per-request to many unknown sellers: a wallet protocol fits.
- One vendor, one invoice, known pricing: an API key with a balance is simpler.
- Either way, set a cap per call and keep the model out of the key.
- Check the AWS page again; GA features change.
Sources
Related posts
More in Agents
- Cap a voiceover batch at $1: tts_create dry_run and max_spend_usd
Preview what a Sume TTS call will cost before it runs, and cap the spend. How dry_run and max_spend_usd work on tts_create, with a 20-line cost example.
- Claude Code 2.1.289 agent.spawn: teammates share one Sume queue
Claude Code 2.1.289 adds agent.spawn for teammates. Teammates sharing a Sume workspace share its concurrency limit and queue, so plan the width of the fan-out.
- Claude Desktop catch-up run after wake: idempotency key for Sume
Desktop runs one catch-up task after sleep, maybe hours late. Use a date-based idempotency_key, dry_run and max_spend_usd so Sume bills once.
- Claude Desktop scheduled task skipped? Computer asleep vs Sume cron
Desktop scheduled tasks only fire while the app is open and the computer is awake. Where a Sume Scheduled cron run differs and when to use each.
Written by Sume