Claude Code routine skips approvals: cap Sume calls with script_run
A routine can use every tool without asking. Sume's script_run bounds a batch of calls with max_calls and max_paid_calls, so one run cannot fan out.

A Claude Code routine runs autonomously with no permission-mode picker and no approval prompts during the run, and the routines page says Claude can use every tool in the session, writes included. If one of those tools is Sume's hosted MCP, a single loop can submit many paid creates before anyone looks. Sume's script_run is built for batches like that: one call runs a short program that makes the child calls, bounded by timeout_seconds, max_calls and max_paid_calls.
Routine behavior is from Anthropic's routines documentation, read on 2026-10-03; script_run is described in Sume's MCP tools and gates.
What does the routine do on its own?
Routines run in the cloud with no permission-mode picker. All connected MCP connectors are included by default, so remove the ones the task does not need before you save. That is the first guardrail; the second is whatever limits the connector itself offers.
What does script_run bound?
The docs describe script_run as a short JavaScript program run on the Sume side that calls tools in a loop, in parallel or conditionally, and returns one value. Inside it, sume.call(name, arguments) runs a tool with the same gates, redaction and errors as a direct call, and paid creates still need their own idempotency_key. The response includes the returned value, a calls[] journal and the child jobs[] to hand to jobs_wait.
| Parameter | Bound | Note |
|---|---|---|
timeout_seconds | 5 to 55 | Wall time for the program |
max_calls | You set it | All child calls |
max_paid_calls | You set it | Paid child calls only |
How does that fit a routine?
Tell the routine prompt to submit batches through script_run only, with max_paid_calls set to the number of items you expect. If the model's plan wants more, the journal shows where the program stopped instead of a surprise bill. Combine that with an idempotency_key per child and max_spend_usd on each paid create, which Sume enforces only when it is sent.
Also keep the OAuth session read-only unless the routine truly writes. An mcp:read session sees only read-only tools, and mutating or paid calls return insufficient_scope.
What should the prompt say?
- Submit more than two similar creates through one
script_run, never as separate loop turns. - Set
max_paid_callsto the item count andmax_callsjust above it. - Pass
max_spend_usdand a freshidempotency_keyon every paid child. - Wait on the returned
jobs[]withjobs_wait, which holds for at most 55 seconds per slice.
What is still not covered?
The cap bounds one program, not the number of times a routine fires. Pair it with the per-routine run limits Anthropic documents and a per-run dollar cap on any Agent Completion the routine submits.
Sources
Related posts
More in Developers
- Where to keep a Sume API key in a Claude Code routine
Environment variables are readable by anyone using the environment. On Pro and Max an API credential hides the key from Claude. What changes on Team plans.
- Claude Code mcp_server_errors: fail CI when Sume never loaded
In stream-json runs Claude Code reports a skipped MCP entry in mcp_server_errors. Check it with jq before a CI job spends on Sume, then verify with mcp_health.
- Claude Code token usage vs Sume spend: two meters, one session
Claude Code's token totals and Sume's generation spend are billed in different places. Log tokens with a mod, read Sume's wallet with usage_get, and compare.
- claude plugin install --config: setting a bundled MCP server
Claude Code 2.1.285 added claude plugin install --config for bundled MCP server settings. What to put there for a Sume plugin, and what never to.
Written by Sume