Claude Code hooks on Sume tool calls: check the top-level guards
A Claude Code hook that gates paid Sume MCP calls should read the top-level idempotency_key, dry_run and max_spend_usd, and deny when input is unreadable.

If you run a Claude Code hook that inspects Sume tool calls, read the top-level arguments idempotency_key, dry_run and max_spend_usd, and deny when you cannot read them. The job body, such as the prompt and model, sits in the nested payload, which a spend guard does not need to parse.
Where do Sume's gates sit?
Per the MCP docs, paid and write tools require idempotency_key. dry_run=true returns an admission and cost preview without submitting. max_spend_usd is optional and enforced only when you provide it. These are top-level tool arguments. The request body for the job goes in the nested payload.
What should a spend hook check?
A hook that blocks spend should read only the top level and fail closed:
- Deny a paid tool call when
idempotency_keyis missing. - Deny it when
max_spend_usdis missing, if your policy requires a cap. Sume itself does not. - Treat an unreadable or empty input as a deny, never an allow.
- Do not parse
payloadto guess a price. Usedry_runorgeneration_admission_preview.
Is a hook enough?
No. A hook runs on the client. The scope is the server-side limit: OAuth mcp:read hides write and paid tools entirely, and there is no mcp:paid scope. See Safe automation for the split.
Sources
Related posts
More in Developers
- claude -p --max-budget-usd does not cap Sume renders
Claude Code's --max-budget-usd is a client-side estimate of API spend in print mode. Pair it with max_spend_usd on every paid Sume call and leave headroom.
- claude -p --max-turns exits with an error: Sume job in flight
When --max-turns ends a CI run, a Sume job may still be rendering. Keep the job id in the output, resume with jobs_wait, and never repeat the paid create.
- Claude Code 2.1.288: MCP calls that ran twice, and paid Sume calls
2.1.288 fixed MCP tool calls sometimes running twice when a remote result was over 16 MB or unparsable. Why every paid Sume call needs an idempotency_key.
- claude -p --permission-prompts none: Sume tools in CI
With --permission-prompts none, prompts nobody can answer are denied. Which Sume tools still run? Read-only OAuth ones do; paid ones need mcp:write.
Written by Sume