Cloudflare paidTool pricing when a Sume run sits behind it
If a Cloudflare paidTool wraps a Sume Agent Completion, set the tool price above the run's generation_spend_cap_usd so one sale cannot lose money.

Make the paidTool price higher than the generation_spend_cap_usd you pass to Sume. The cap is the most the run may spend on generation, so a price above it keeps each paid call from costing you more than you charged. This is arithmetic about margin, not a Cloudflare feature.
Cloudflare's x402 page shows this.server.paidTool(name, description, price, inputSchema, annotations, handler), with the price in USD. A caller that has not paid gets a 402 with payment requirements, pays, and retries with proof. Your handler runs only after that.
Pieces and who owns them
| Piece | Detail | Owner |
|---|---|---|
paidTool price | USD, set per tool | Cloudflare Agents SDK |
X402Config | network base or base-sepolia, recipient wallet, facilitator https://x402.org/facilitator | Cloudflare Agents SDK |
| Test setup | base-sepolia with Circle faucet USDC | Cloudflare docs |
generation_spend_cap_usd | Required; no default; missing means 400 | Sume Agent Completions |
Idempotency-Key | Same key returns the original receipt with idempotency_hit: true | Sume Agent Completions |
Handler sketch
The function below is what a paid handler would call after payment is verified. It creates the run with a cap derived from the price and returns the receipt id for polling. Pass the payment id as the idempotency key so a retried request does not start a second run.
export async function startRun(task: string, priceUsd: number, paymentId: string) {
const res = await fetch("https://api.sume.com/v1/agent/completions", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.SUME_API_KEY}`,
"Content-Type": "application/json",
"Idempotency-Key": paymentId,
},
body: JSON.stringify({
instruction: task,
generation_spend_cap_usd: Math.max(0.5, priceUsd / 2),
}),
});
if (res.status !== 202) throw new Error(`Sume ${res.status}`);
const { data } = await res.json();
return data.id as string;
}Things to watch
- Pick the cap from your own cost data, not from this example's
priceUsd / 2. - The run is async: return the
agrun_id and let the buyer poll, or use a run webhook. - Test the 402 path on base-sepolia before real USDC.
- Service-account keys cannot create Agent Completions; use a user API key with the write scope.
Sources
Related posts
More in Developers
- Cloudflare Sandbox SDK 1.0: run the Sume SDK inside one
The @sume-com/sdk has no runtime dependencies and needs only fetch and WebCrypto, so it can run in a sandbox. Pass the key as an env var, server-side only.
- Cloudflare Worker for Sume webhooks: log fields a dashboard needs
Cloudflare added Workers Observability to Custom Dashboards on Oct 1. A Sume webhook Worker should log event, job_id, outcome and the secret fingerprint.
- Codex 0.160 agent history 'Show more': recover Sume jobs by job list
Codex CLI 0.160.0 adds Show more pagination to agent command center history. If a thread scrolls away, Sume's GET /v1/jobs list still holds every job.
- Computer-use agent or API call: use Sume jobs, not clicks
OpenAI added computer use to its Agents API on Sep 29, 2026. For media generation, an agent should call Sume's API or MCP tools rather than click a dashboard.
Written by Sume