Claude Code auto mode with Sume's MCP: paid-call gates still apply
In Claude Code auto mode a classifier reviews each action. On Sume's MCP, paid calls still need idempotency_key, and dry_run and max_spend_usd stay available.

In auto mode a classifier checks actions before they run, and that decides whether Claude Code asks you. It does not replace Sume's own gates: every paid or write call on Sume's MCP still needs an idempotency_key, dry_run=true still previews cost, and max_spend_usd is enforced when you pass it. Put a spend cap in the call, not only in the permission mode.
Auto mode facts are from the Claude Code auto-mode classifier page; Sume facts from MCP tools and gates and MCP OAuth and API keys, read 2026-09-30.
What does auto mode do?
The page says that in auto mode a classifier checks actions such as shell commands and network requests before they run. Where server-side checks are on, the server performs them as part of the session's own model requests, at no charge. If the server's checks do not reach your session, for example behind an LLM gateway, Claude Code makes its own classifier requests, billed as token usage. CLAUDE_CODE_AUTO_MODE_SERVER=0 turns the server checks off; the page calls it a temporary setting.
Which Sume gates apply to each call?
| Gate | Required? | Meaning in the docs |
|---|---|---|
idempotency_key | Required on write and paid tools | Stable key for transport and dedup, not human approval |
dry_run=true | Optional | Admission and cost preview only; the job is not submitted |
max_spend_usd | Optional | Enforced only when provided |
OAuth mcp:read | Default on consent | Sees read-only tools only |
Does an auto-mode approval count as human approval on Sume?
No. The docs describe idempotency_key as transport dedup, "not human approval", and say there is no mcp:paid scope: paid submits go through wallet admission. So the only human checkpoints are the ones you configure on the Claude Code side. See ask rules for paid MCP tools.
How should I set it up?
Connect with claude mcp add --transport http sume https://mcp.sume.com/mcp and claude mcp login sume. Leave Write off at consent if the session should only read. For paid work, have the prompt ask for dry_run=true first and pass max_spend_usd on the real call; see dry-run and spend caps.
Sources
Related posts
More in Developers
- Claude Code --bare and MCP: name the Sume server with a key
Claude Code --bare connects only MCP servers named on the command line. To use Sume there, name the server with an API-key header; no browser sign-in needed.
- MCP server instructions field: the new /context row, and Sume's
Claude Code 2.1.283 counts MCP server instructions as their own /context row. Sume returns instructions at initialize and keeps long guidance out of tool text.
- CLAUDE_CODE_DISABLE_WEB_FETCH: what Sume crawl tools do
CLAUDE_CODE_DISABLE_WEB_FETCH turns off Claude Code's WebFetch tool. Sume's crawl_* tools come from an MCP server, so they are a separate path.
- Claude Code MCP connection timeout: startup wait vs a Sume call
Claude Code 2.1.284 waits up to 10 s for a connecting MCP server on resumed calls and 2 s on a non-interactive first turn. Sume tool calls hold at most 55 s.
Written by Sume