Claude 'Allow always' on a paid Sume tool: what still caps spend
Claude custom connectors let you approve a tool once and keep approving it. For a paid Sume tool, the scope, idempotency key and max_spend_usd still apply.

Claude's custom connector guide (read 2026-10-05) tells users to review each tool approval request before clicking Allow always, and to disable irrelevant tools in the Search and tools menu. Permissions arrive through OAuth at setup, and Claude can only reach what you authorized.
Allow always is a convenience on the client. It is not a spend control on the server. That matters for a connector whose tools cost money, which is the case for Sume's generate_video, generate_image and tts_create.
The server-side limits that remain
- Scope: a session granted only
mcp:readcannot call a write or paid tool; it getsinsufficient_scope(OAuth and API keys). - Idempotency: write and paid calls must carry
idempotency_key; a repeated key is a replay, not a second job. - Cap:
max_spend_usdis enforced when the call includes it, anddry_run=truepreviews cost without submitting. - Wallet: spend is wallet and admission; a job that cannot be reserved is refused before provider work starts.
A setup that survives Allow always
Connect read-only first and call mcp_health and tools_list. Grant mcp:write only on the connector you use to generate. Then put the cap in the instruction, not in your memory of it: tell Claude to call generation_admission_preview or use dry_run and pass max_spend_usd on every paid call. The Safe automation page says paid actions should be explicit and kept separate from read-only operations, which is the same idea.
Disable the tools you will not use. A connector that exposes crawl, upload and avatar tools to a session that only needs generate_image has more surface than the task needs.
Sources
Related posts
More in Agents
- Sonnet 5.5 scores 70.6% on Terminal-Bench 4.0: cap Sume calls anyway
A benchmark score says how well Sonnet 5.5 finishes tasks, not what a Sume call may cost. Put generation_spend_cap_usd on every Agent Completion it starts.
- Clef-flash as a yes/no gate before a paid Sume Agent Completion
Cloudflare's Clef-flash returns typed answers with probabilities. Put one in front of POST /v1/agent/completions as a filter, keep the spend cap as the guard.
- A decision model's confidence is not a spend cap: Sume's real gates
Strands Decider and Clef return confidence scores. Only the Sume gates in this table, from idempotency_key to the required spend cap, limit what a run can cost.
- DeepSeek V4.1 Flash sees images: hand one to a Sume Agent Completion
V4.1 Flash is described as natively multimodal. To act on an image with Sume, pass it as an input_image attachment on an Agent Completion, up to 30 per run.
Written by Sume