Codex Cloud background tasks: three Sume guardrails to set first

OpenAI's Codex Cloud runs tasks in the background while you are away. Before one can call Sume, set read-only scope, idempotency keys and a hard spend cap.

5 min readSume
All posts

Codex Cloud, announced at OpenAI DevDay 2026, runs tasks while your laptop is closed, so nobody is at the keyboard to approve a paid call. If such a task can reach Sume, set three guardrails first: a read-only credential unless the task must submit, an idempotency_key on every write, and a hard spend ceiling per call or per run. Sume enforces the first two server-side and the third whenever you provide it.

What is known

The DevDay thread lists Codex Cloud for running background tasks, plus an enhanced CLI, automated code review and scheduled security vulnerability scanning. The Codex changelog shows terminal input approval enabled by default for commands with elevated permissions, and 0.160 adding opt-in Guardian review that can retrieve earlier user instructions. None of the pages read describes how a Codex Cloud task attaches an MCP server, so this post assumes you have configured access yourself and covers only the Sume side.

The three guardrails

Each guardrail maps to a documented Sume control:

Guardrails for an unattended Sume caller (read 2026-10-04)
GuardrailSume controlFailure it prevents
Read-only by defaultOAuth mcp:read hides mutating and paid toolsA review task renders video
Repeat-safe writesidempotency_key required on write and paid toolsA retried step paying twice
Ceiling on spendmax_spend_usd, or generation_spend_cap_usd on Agent CompletionsA loop draining the wallet

Details worth knowing

Per MCP tools and gates, max_spend_usd is enforced only when you provide it, so your task prompt or wrapper must always send it. There is no mcp:paid scope; spend is wallet and admission based, so a write-capable session can spend as far as the balance allows. For Agent Completions the cap is required, which is the safer default for an unattended caller.

An API key sees the full tool set, so for a background task prefer a dedicated key for that purpose, kept in the platform's secret store, and rotate it if it appears in logs. Safe automation lists what never to log: keys, signed URLs, raw private media URLs.

A short checklist

  • Start the task with mcp_health and account_me to confirm which identity and scopes it has.
  • Have it call generation_admission_preview before any burst of paid calls.
  • Make it write the job id to its report immediately after each submit.
  • Let it finish by reading jobs_status, not by waiting, since the job continues if the task ends.
  • Review the report and the Sume usage list the next morning.

Sources

Related posts

More in Agents

All Agents posts

Written by Sume