Computer use origin approval is not a spend approval

OpenAI's computer use approves each new website origin, not spend. When such an agent calls Sume, the spend check is dry_run, max_spend_usd and the wallet.

4 min readSume
All posts

No. The approval OpenAI's hosted browser asks for is about website origins, not money. If a computer-use agent also calls Sume, the spend control is on the Sume side: dry_run, an optional max_spend_usd, and the workspace wallet.

The computer use guide, read 2026-09-30, says the browser requires the user's approval before accessing each new website origin, including public websites, and that enabling network access does not approve these requests. A pending computer_use_approval_request with request type browser_origin_access appears in required_actions, and you collect approve, deny or cancel.

What does a Sume tool call check instead?

Sume's MCP tools and gates lists the gates. None of them is a human approval step.

Safety gates on the hosted MCP server, read 2026-09-30.
GateWhat the docs say
idempotency_keyRequired on write and paid tools; stable key for transport/dedup, not human approval
dry_run=trueOptional; admission/cost preview only, does not submit the job
max_spend_usdOptional; enforced only when provided
ScopeWrite and paid tools hidden until mcp:write or an API key; no mcp:paid scope

Where should the spend approval live?

In your own agent loop. Before the first paid call, have the agent run dry_run=true or generation_admission_preview, show the preview to the user, and submit only after approval. Pass max_spend_usd on the submit so the cap is actually enforced, since it applies only when provided. A pattern for a human gate around paid tools is in OpenAI Agents SDK human-in-the-loop paid tools.

Does approving an origin grant access to Sume?

Nothing in either source says so. Sume access comes from the session: an API key or OAuth mcp:write makes the write and paid tools visible, and spend is wallet and admission. Treat the two approvals as separate, and give the agent a key you can revoke.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume