Claude Code routine skips approvals: cap Sume calls with script_run

A routine can use every tool without asking. Sume's script_run bounds a batch of calls with max_calls and max_paid_calls, so one run cannot fan out.

5 min readSume
All posts

A Claude Code routine runs autonomously with no permission-mode picker and no approval prompts during the run, and the routines page says Claude can use every tool in the session, writes included. If one of those tools is Sume's hosted MCP, a single loop can submit many paid creates before anyone looks. Sume's script_run is built for batches like that: one call runs a short program that makes the child calls, bounded by timeout_seconds, max_calls and max_paid_calls.

Routine behavior is from Anthropic's routines documentation, read on 2026-10-03; script_run is described in Sume's MCP tools and gates.

What does the routine do on its own?

Routines run in the cloud with no permission-mode picker. All connected MCP connectors are included by default, so remove the ones the task does not need before you save. That is the first guardrail; the second is whatever limits the connector itself offers.

What does script_run bound?

The docs describe script_run as a short JavaScript program run on the Sume side that calls tools in a loop, in parallel or conditionally, and returns one value. Inside it, sume.call(name, arguments) runs a tool with the same gates, redaction and errors as a direct call, and paid creates still need their own idempotency_key. The response includes the returned value, a calls[] journal and the child jobs[] to hand to jobs_wait.

script_run limits (read 2026-10-03)
ParameterBoundNote
timeout_seconds5 to 55Wall time for the program
max_callsYou set itAll child calls
max_paid_callsYou set itPaid child calls only

How does that fit a routine?

Tell the routine prompt to submit batches through script_run only, with max_paid_calls set to the number of items you expect. If the model's plan wants more, the journal shows where the program stopped instead of a surprise bill. Combine that with an idempotency_key per child and max_spend_usd on each paid create, which Sume enforces only when it is sent.

Also keep the OAuth session read-only unless the routine truly writes. An mcp:read session sees only read-only tools, and mutating or paid calls return insufficient_scope.

What should the prompt say?

  • Submit more than two similar creates through one script_run, never as separate loop turns.
  • Set max_paid_calls to the item count and max_calls just above it.
  • Pass max_spend_usd and a fresh idempotency_key on every paid child.
  • Wait on the returned jobs[] with jobs_wait, which holds for at most 55 seconds per slice.

What is still not covered?

The cap bounds one program, not the number of times a routine fires. Pair it with the per-routine run limits Anthropic documents and a per-run dollar cap on any Agent Completion the routine submits.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume