Ship a Sume Claude Code plugin off by default: defaultEnabled false
A manifest can set defaultEnabled to false, so a Sume plugin with paid tools starts disabled until someone turns it on. What persists after updates.

Set "defaultEnabled": false in plugin.json and a Sume plugin installs without turning on. The plugin manifest reference says the field decides whether the plugin starts enabled when the user has not set it in enabledPlugins, and it defaults to true. For a plugin that brings in Sume's paid tools, off by default means nobody generates video by accident on the day the plugin arrives.
The same reference warns that a marketplace entry's own defaultEnabled overrides the manifest's, and that a user's choice persists across updates.
How the setting behaves
All rows come from the manifest reference.
| Field | Effect | For a Sume plugin |
|---|---|---|
| defaultEnabled | Starts enabled unless the user has set it; default true | Use false for a plugin that exposes paid tools |
| Marketplace entry defaultEnabled | Overrides the manifest value | Check the marketplace entry too |
| enabledPlugins entry | Once written it persists across updates | Changing defaultEnabled later does not change existing users |
| dependencies | Plugins that must be enabled for this one to work | A plugin that an enabled plugin depends on starts enabled regardless |
| userConfig required | Dialog rejects an empty value | Ask for the key when the user turns it on |
Steps
Add defaultEnabled: false and a userConfig option for the Sume API key marked sensitive and required. Install the plugin in a clean profile, confirm it is listed as disabled, then enable it and enter the key. Call mcp_health and then tools_list. With an API key, Sume returns the full tool set; with OAuth and no Write opt-in, only the read tools.
- Use OAuth with Write off for a plugin whose job is research and discovery.
- Document in the plugin description that paid tools need
idempotency_keyand thatmax_spend_usdis optional. - Bump
versionwhen you change defaults, because setting it pins users to that version until you change it.
Choosing the default for your audience
For a personal plugin you use daily, the default hardly matters. For a plugin you give to a team, off by default is a quiet form of consent: the person who turns it on has read the description and knows the tool can spend money. For a read-only plugin that only lists catalogs and job status, leave it on, since nothing is at stake.
Whichever you choose, say it in the description. A plugin that installs disabled and says nothing generates a support message in the first hour.
What Sume does not do
Sume does not know whether a plugin is enabled and does not enforce the default. The setting is a convenience on the client. A user who enables the plugin with an API key gets the full hosted tool set, and Sume's own gates, the idempotency key, the optional spend cap and wallet admission, are what remain.
Sources
Related posts
More in Developers
- Plugin headersHelper cannot read user_config: where the Sume key goes
Claude Code rejects ${user_config.*} inside an MCP headersHelper. Use the headers field for a Sume API key, or fetch the key inside the helper script yourself.
- Name your Sume plugin right: claude- and anthropic- prefixes fail
claude plugin validate errors on plugin names that pass as Anthropic's own. Pick a name for a Sume hosted MCP plugin that validates, and see what still loads.
- claude plugin validate --strict in CI: what it checks in a Sume entry
Run claude plugin validate with --strict so warnings fail the build. The MCP checks that hit a Sume entry: undeclared keys, bad URLs, literal credentials.
- Claude tool search limits: 200-char regex, 500-char BM25, 5 results
Claude's tool search tool has fixed limits on pattern length, results and deferred tools. What they mean for a Sume hosted MCP tool list.
Written by Sume