Claude Code 2.1.283 allowManagedPermissionRulesOnly: Sume tools
Under allowManagedPermissionRulesOnly, Claude Code 2.1.283 stops marketplace plugins from pre-approving their own tools. What it means for Sume paid tools.

If your organisation sets allowManagedPermissionRulesOnly, a plugin from a marketplace, claude.ai or npm can no longer pre-approve its own tools through allowed-tools in Claude Code 2.1.283 (2026-09-25). Only official Anthropic sources or sources vouched for by managed settings keep that ability, so a third-party plugin cannot quietly allow Sume's paid tools.
That is the behaviour you want for a spend-capable server, and it means the approval has to come from your managed rules.
What changed
Before 2.1.283, a plugin's allowed-tools list could pre-approve tools even in a locked-down managed setup. Now, under the managed-only setting, that pre-approval is honoured only for official Anthropic or managed-vouched sources.
At a glance
| Source | Pre-approves via allowed-tools |
|---|---|
| Plugin from marketplace, claude.ai or npm | No |
| Official Anthropic source | Yes |
| Source vouched for by managed settings | Yes |
| Managed permission rules | Yes |
Applying it to Sume
Sume has one hosted MCP server with two OAuth scopes. mcp:read is required and shows read tools; mcp:write is opt-in and exposes mutating and paid tools. There is no separate paid scope, so the permission rule is where you express which paid tools may run unattended.
Write your Sume rules in managed settings, and keep per-call guards in the tool arguments: idempotency_key is required on write and paid calls, and max_spend_usd is available as a ceiling.
- Put Sume allow rules in managed settings, not plugin manifests.
- Allow read tools broadly and write tools narrowly.
- Add a hook or spend cap for unattended runs.
Limits and what is not verified
The changelog describes the vouching mechanism only briefly; consult Anthropic's managed settings documentation for the exact keys. I did not run Claude Code under this setting against Sume.
Sources
Related posts
More in Integrations
- Claude Code cloud sessions: where Sume hosted MCP comes from
In Claude Code cloud sessions the host passes in MCP servers from your claude.ai organization settings. Add Sume as a connector there, not in a local file.
- Claude Desktop Code tab subagents lose a "memory" MCP server
Claude Code 2.1.288 fixed subagents in the Claude Desktop Code tab getting no tools from a user MCP server named memory. Why Sume stays named sume.
- Claude Desktop managed connector OAuth client change and Sume
Claude Desktop 2.110 stops connecting managed connectors that have their own OAuth client but no credentials. Sume requires sign-in either way.
- Claude Desktop mcpToolTimeoutSec 180 s: does Sume jobs_wait fit?
Claude Desktop 2.110 added mcpToolTimeoutSec, default 180 seconds. Sume jobs_wait holds at most 55 seconds, so the default fits with room to spare.
Written by Sume