Codex Cloud background tasks: three Sume guardrails to set first
OpenAI's Codex Cloud runs tasks in the background while you are away. Before one can call Sume, set read-only scope, idempotency keys and a hard spend cap.

Codex Cloud, announced at OpenAI DevDay 2026, runs tasks while your laptop is closed, so nobody is at the keyboard to approve a paid call. If such a task can reach Sume, set three guardrails first: a read-only credential unless the task must submit, an idempotency_key on every write, and a hard spend ceiling per call or per run. Sume enforces the first two server-side and the third whenever you provide it.
What is known
The DevDay thread lists Codex Cloud for running background tasks, plus an enhanced CLI, automated code review and scheduled security vulnerability scanning. The Codex changelog shows terminal input approval enabled by default for commands with elevated permissions, and 0.160 adding opt-in Guardian review that can retrieve earlier user instructions. None of the pages read describes how a Codex Cloud task attaches an MCP server, so this post assumes you have configured access yourself and covers only the Sume side.
The three guardrails
Each guardrail maps to a documented Sume control:
| Guardrail | Sume control | Failure it prevents |
|---|---|---|
| Read-only by default | OAuth mcp:read hides mutating and paid tools | A review task renders video |
| Repeat-safe writes | idempotency_key required on write and paid tools | A retried step paying twice |
| Ceiling on spend | max_spend_usd, or generation_spend_cap_usd on Agent Completions | A loop draining the wallet |
Details worth knowing
Per MCP tools and gates, max_spend_usd is enforced only when you provide it, so your task prompt or wrapper must always send it. There is no mcp:paid scope; spend is wallet and admission based, so a write-capable session can spend as far as the balance allows. For Agent Completions the cap is required, which is the safer default for an unattended caller.
An API key sees the full tool set, so for a background task prefer a dedicated key for that purpose, kept in the platform's secret store, and rotate it if it appears in logs. Safe automation lists what never to log: keys, signed URLs, raw private media URLs.
A short checklist
- Start the task with
mcp_healthandaccount_meto confirm which identity and scopes it has. - Have it call
generation_admission_previewbefore any burst of paid calls. - Make it write the job id to its report immediately after each submit.
- Let it finish by reading
jobs_status, not by waiting, since the job continues if the task ends. - Review the report and the Sume usage list the next morning.
Sources
Related posts
More in Agents
- Cursor Projects coordinator fan-out: size waves from generation_limits
A Cursor coordinator that delegates to subagents can overrun a Sume workspace. Budget new in-flight jobs from generation_limits, not from wave_size_hint.
- Parallel tool calls on a voice agent: one idempotency key each
ElevenLabs agents default enable_parallel_tool_calls to true. If tools start paid jobs, give each call its own key and wait on all job ids in one batch.
- Gemini 4 Argon is announced but not public: what to run today
Google announced Gemini 4 Argon on Sept 30 with access limited to cyber defenders. Here is what a Sume Format run uses as its orchestrator meanwhile.
- Gemini managed agents background:true vs a Sume Format 202 receipt
Both return an id to poll instead of holding the connection. Compare the Gemini background flag with the Sume Format run receipt and its four URLs.
Written by Sume