Claude 'Allow always' on a paid Sume tool: what still caps spend

Claude custom connectors let you approve a tool once and keep approving it. For a paid Sume tool, the scope, idempotency key and max_spend_usd still apply.

4 min readSume
All posts

Claude's custom connector guide (read 2026-10-05) tells users to review each tool approval request before clicking Allow always, and to disable irrelevant tools in the Search and tools menu. Permissions arrive through OAuth at setup, and Claude can only reach what you authorized.

Allow always is a convenience on the client. It is not a spend control on the server. That matters for a connector whose tools cost money, which is the case for Sume's generate_video, generate_image and tts_create.

The server-side limits that remain

  • Scope: a session granted only mcp:read cannot call a write or paid tool; it gets insufficient_scope (OAuth and API keys).
  • Idempotency: write and paid calls must carry idempotency_key; a repeated key is a replay, not a second job.
  • Cap: max_spend_usd is enforced when the call includes it, and dry_run=true previews cost without submitting.
  • Wallet: spend is wallet and admission; a job that cannot be reserved is refused before provider work starts.

A setup that survives Allow always

Connect read-only first and call mcp_health and tools_list. Grant mcp:write only on the connector you use to generate. Then put the cap in the instruction, not in your memory of it: tell Claude to call generation_admission_preview or use dry_run and pass max_spend_usd on every paid call. The Safe automation page says paid actions should be explicit and kept separate from read-only operations, which is the same idea.

Disable the tools you will not use. A connector that exposes crawl, upload and avatar tools to a session that only needs generate_image has more surface than the task needs.

Sources

Related posts

More in Agents

All Agents posts

Written by Sume