Claude Managed Agents auto permission and Sume paid MCP calls
The auto policy evaluates each MCP tool call server-side. Sume has no paid scope, so pair auto with dry_run, max_spend_usd and a scope-limited session.

Claude Managed Agents' auto permission policy has the server evaluate each agent or MCP tool call and run it, deny it, or pause for approval. Sume cannot tell the policy a call is paid, because there is no mcp:paid scope, so put the limits on the Sume side: a read-only session where no spend is wanted, dry_run for previews and max_spend_usd as a per-call cap.
Vendor facts are from the Claude release notes read 2026-10-01; Sume facts from OAuth and API keys and tools and gates.
What does auto do?
The September 10, 2026 note says permission policies now include auto: "the server evaluates each agent or MCP tool call and runs it, denies it, or pauses for your approval." agent.tool_use and agent.mcp_tool_use events report how each call was evaluated in an evaluation field alongside evaluated_permission. The notes do not say what criteria the evaluation uses, so do not assume it understands cost.
What does Sume enforce on its own?
Sume's gates are independent of the client's permission policy.
| Gate | Behavior |
|---|---|
mcp:read session | Only read-only tools are visible; write returns insufficient_scope |
mcp:write or API key | Mutating and paid tools are visible |
idempotency_key | Required on write and paid calls; dedup, not approval |
dry_run | Optional cost preflight |
max_spend_usd | Enforced only when provided |
mcp:paid | Does not exist; spend is wallet and admission |
How should I combine them?
Decide first whether this agent should spend at all. If not, connect with OAuth mcp:read only and a paid tool will not even be listed. If it should, give it write access and instruct it to call with dry_run first and always pass max_spend_usd, because the cap is not applied when omitted. Treat an auto allow as "the policy saw no problem", not "Sume approved the spend". Related client-side guards: Claude Code auto mode.
How do I audit it afterwards?
Use the agent.mcp_tool_use events for what the policy decided, and read the Sume job ids in the tool results for what was submitted. If a call retried, the same idempotency_key returns the original rather than billing again, so keep keys stable per intended generation.
Sources
Related posts
- Claude Code auto mode with Sume's MCP: paid-call gates still apply
- Claude Opus 5.5 and paid MCP tools: preview and cap spend with dry_run
- OpenAI Agents SDK human in the loop for paid tools
- Claude Code permissions ask rule for paid MCP tools
- Fix MCP insufficient_scope on Sume: scopes, missing tools, timeouts
More in Developers
- Claude Opus 5.5 tool_choice any 400: steer Sume tools instead
Opus 5.5 returns 400 for tool_choice any or tool. Use auto, then steer to generate_image with instructions and tools_schema, and keep dry_run before paid calls.
- Codex MCP input schema budget: how many Sume tools you load
Codex 0.158.0 makes MCP and Code Mode input schema budgets configurable. Sume keeps tool descriptions short and shows fewer tools to a read-only session.
- Apply a LUT to video by API: no .cube file, use lutrgb curves
Sume's video filter cannot load a .cube LUT because lut3d is not allowlisted. Per-channel curves with lutrgb or lutyuv are the supported way to grade.
- Deepgram Flux numerals toggle vs Sume STT digits
Deepgram Flux can switch numerals on mid-stream for PINs and phone numbers. Sume STT is a batch job with fixed provider settings and no numerals flag.
Written by Sume