claude -p --permission-prompt-tool with Sume paid jobs

Headless claude -p can route permission prompts to an MCP tool. For Sume paid jobs, keep idempotency_key stable and wait with jobs_wait in 55s slices.

4 min readSume
All posts

With claude -p --permission-prompt-tool <tool>, permission prompts go to an MCP tool you name instead of a person. Since v2.1.285 that includes a background subagent's request. Whatever that tool answers, a paid Sume call still needs its own idempotency_key, and a local timeout is never a reason to submit the create again: re-read the job with jobs_wait.

Claude Code facts are from its CLI reference and release notes; Sume facts from MCP tools and gates and Jobs and results, read 2026-09-30.

What does the flag do?

The CLI reference says it specifies an MCP tool to handle permission prompts in non-interactive mode. Claude Code waits for that tool's MCP server to connect before the first turn, up to the MCP_TIMEOUT startup timeout, 30 seconds by default. It cannot approve an MCP tool marked as requiring user interaction. The v2.1.285 notes say a background subagent's permission request now goes to the prompt tool instead of being auto-denied.

What still protects a paid Sume call?

Sume-side gates for headless runs, read 2026-09-30
LayerControlSource
Claude Code--permission-prompt-tool answers the promptCLI reference
Sume's MCPidempotency_key required on write and paid toolsMCP tools and gates
Sume CLI--confirm-paid for generation that can reserve or spend creditsAgent skills (CLI)
Waitingjobs_wait holds at most 55s per callJobs and results

How do I wait on a job in a -p run?

Call jobs_wait with the job id. Each call holds at most 55 seconds (default 50); on wait_slice_expired, call it again with the same ids rather than resubmitting. This keeps one turn from depending on a single long request; see jobs_wait for long video jobs.

What should the prompt tool decide?

Keep it simple: allow read tools, and for paid calls allow only when the input carries max_spend_usd and an idempotency_key you generated before the run. Connect Sume with claude mcp add --transport http sume https://mcp.sume.com/mcp; the unattended setup is in headless MCP config for Sume video, and connect-time waits in the startup timeout post.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume