Cursor Automations webhook: start a Sume agent run with a spend cap

A Cursor Automation can call Sume Agent Completions from a webhook-triggered run. Send generation_spend_cap_usd and an Idempotency-Key on every call.

4 min readSume
All posts

Yes. Run the Automation, and have the step that needs media POST to https://api.sume.com/v1/agent/completions with a required generation_spend_cap_usd and an Idempotency-Key, so an unattended run cannot spend past a number you chose.

Cursor Automations start from several triggers. Its docs list scheduled runs, source control events, Slack, webhooks, Linear, Sentry and PagerDuty. For a webhook, the docs say you save the automation first, which generates a webhook URL to call and an API key for authentication. Nobody is watching these runs, which is exactly the setting Sume's spend caps were built for.

Two ways to give the Automation Sume

You can connect the hosted MCP to the Automation, or call the REST API from a script. Cursor's docs advise connecting only servers you trust with the permissions the automation needs, and that is the question to answer first.

Connecting an Automation to Sume (read 2026-10-03)
OptionCredentialWhat the run can doSpend control
Hosted MCP at mcp.sume.com/mcpSume API key or OAuth sessionAn API key session sees the full tool set, paid tools includedmax_spend_usd per call when passed; wallet admission
REST Agent CompletionAPI key with agent_completions:writeHands the whole task to the Sume agentgeneration_spend_cap_usd, required, no default

The REST call

Agent Completions return 202 with an agent.run receipt, and you poll it. The scope needed is agent_completions:write; keys created before the feature shipped lack it, and service-account keys get a 403. The Idempotency-Key makes a replayed webhook return the original receipt rather than a second run.

import json, os, urllib.request

key = os.environ["SUME_API_KEY"]
body = {
    "instruction": "Make a 6 second vertical product clip from the attached brief.",
    "generation_spend_cap_usd": 2,
}
req = urllib.request.Request(
    "https://api.sume.com/v1/agent/completions",
    data=json.dumps(body).encode(),
    headers={
        "Authorization": f"Bearer {key}",
        "Content-Type": "application/json",
        "Idempotency-Key": "automation-pr-4821-clip-1",
    },
    method="POST",
)
with urllib.request.urlopen(req) as res:
    run = json.load(res)["data"]
print(run["id"], run["status"], run["status_url"])

Run as Me or as a service account

Cursor lets an Automation run as you, billed to you, or as a team service account billed to the team's usage pool. That is Cursor's billing. On the Sume side the credential is separate: an API key you create in the dashboard. Note that a Sume service-account key cannot create Agent Completions, so use a normal key with the right scopes for this call.

Pick the idempotency key from the event, such as the pull request number, so a retried webhook cannot start a second paid run. Poll GET /v1/agent-runs/{id} until the status is completed, failed or canceled, or register a webhook on the completion; see run webhooks.

Sources

Related posts

More in Agents

All Agents posts

Written by Sume