ChatGPT confirms write tools; Sume MCP also gates them by scope
ChatGPT developer mode asks before write actions. Sume's hosted MCP adds a second gate: OAuth mcp:write, an idempotency_key and an optional max_spend_usd.

Two separate controls sit between a ChatGPT prompt and a paid video call, and they answer different questions. ChatGPT's developer mode asks whether you want this tool call to happen. A hosted MCP server decides whether this session may call it at all.
OpenAI's developer mode guide (read 2026-10-05) says write actions require confirmation by default, that you should review the tool input before approving, and that tools without a readOnlyHint annotation are treated as write actions. You can also have ChatGPT remember an approve or deny choice for one tool for a conversation; a new or refreshed conversation asks again.
What Sume checks on its side
Sume's OAuth and API keys page defines two scopes: mcp:read (required) and mcp:write (opt-in, toggled on the consent page, off by default). There is no mcp:paid scope. A read-only session sees only read tools, and a write or paid call returns insufficient_scope.
| Control | Who enforces it | What it decides |
|---|---|---|
| Confirmation dialog | ChatGPT | Whether this call runs now |
| mcp:write scope | Sume MCP server | Whether the session may see or call write and paid tools |
| idempotency_key | Sume, required on write and paid tools | Transport and dedup, not human approval |
| max_spend_usd | Sume, only if you pass it | A spend ceiling for that call |
| Wallet and admission | Sume | Whether the balance and queue can take the job |
What to do with that
Do not treat a clicked Allow as a budget. It approves one input, and the page above says idempotency_key is not human approval. If the model might loop, ask it to call the tool with dry_run=true first and a max_spend_usd, which Sume enforces only when you provide it.
For a read-only connector, leave Write off at consent and let ChatGPT use tools_list, balance_get and jobs_list. Turn Write on only for the sessions that should generate.
Sources
Related posts
More in Agents
- Claude 'Allow always' on a paid Sume tool: what still caps spend
Claude custom connectors let you approve a tool once and keep approving it. For a paid Sume tool, the scope, idempotency key and max_spend_usd still apply.
- Sonnet 5.5 scores 70.6% on Terminal-Bench 4.0: cap Sume calls anyway
A benchmark score says how well Sonnet 5.5 finishes tasks, not what a Sume call may cost. Put generation_spend_cap_usd on every Agent Completion it starts.
- Clef-flash as a yes/no gate before a paid Sume Agent Completion
Cloudflare's Clef-flash returns typed answers with probabilities. Put one in front of POST /v1/agent/completions as a filter, keep the spend cap as the guard.
- A decision model's confidence is not a spend cap: Sume's real gates
Strands Decider and Clef return confidence scores. Only the Sume gates in this table, from idempotency_key to the required spend cap, limit what a run can cost.
Written by Sume