Agent SDK permissionMode omitted: auto mode, Sume gates stay
From Agent SDK 0.3.286 an omitted permissionMode can start in auto mode. Sume's idempotency_key and scope checks run server-side whatever mode you pick.

If you leave permissionMode out in the TypeScript Agent SDK 0.3.286, the choice is now made by Claude Code, so a session can start in auto mode with no manual approvals. Sume does not rely on that prompt: its write and paid tools are gated by scope and idempotency_key on the server.
The SDK change is from the release notes; the gates are from Sume's MCP tools and gates, both read 2026-10-01.
What changed when permissionMode is omitted?
The 0.3.286 notes (2026-09-30) say the SDK now leaves an omitted permissionMode to Claude Code, so a settings defaultMode applies. On third-party providers or with telemetry off, the session starts in auto mode like claude -p. Pass permissionMode: 'default' to keep manual approvals.
Which Sume checks does auto mode not touch?
The client mode decides whether a human is asked. The Sume checks below are evaluated by the hosted MCP server, so a session in auto mode meets the same ones.
| Gate | What the docs say |
|---|---|
idempotency_key | Required on write and paid tools; a stable key for transport and dedup, not human approval |
| Scope | There is no mcp:paid scope; mutating and paid tools need mcp:write or an API key |
| Read-only OAuth | Write and paid calls return insufficient_scope |
| API key session | Full hosted tool set with the same idempotency_key and admission rules |
max_spend_usd | Optional; enforced only when provided |
Should I still pass permissionMode: 'default'?
That is a client policy decision. Keep manual approvals if a person should see each paid call before it goes out. If the agent runs unattended, set max_spend_usd and use dry_run=true first, since the docs describe dry_run as an admission and cost preview that does not submit the job. See also auto mode and Sume paid prompts.
How do I check what a session can call?
Call tools_list for the tools visible to the session and tools_schema with a name for one contract. A read-only OAuth session will not list the mutating tools at all.
Sources
Related posts
More in Developers
- Agent SDK rewind_conversation and a Sume job: find, then cancel
After rewind_conversation or a priority-now message, the MCP call is handled client-side. A submitted Sume job has its own id: find it with jobs_list.
- Claude Code: disable an MCP server mid-session, Sume jobs persist
Switching off an MCP server in Claude Code SDK sessions removes its tools for new calls. Sume jobs already submitted keep running until you read or cancel them.
- Claude API compaction block: keep Sume job ids past the summary
The compact-2026-09-04 beta swaps old messages for a signed compaction block. Keep Sume job ids and keys outside it; re-read with jobs_status.
- Claude mcp_tool_listing pin: what a Sume tool list depends on
A pinned mcp_tool_listing holds the Sume tool list fetched for one session scope. Sume's list depends on mcp:read vs mcp:write and never pushes list changes.
Written by Sume