Cursor Automations webhook: start a Sume agent run with a spend cap
A Cursor Automation can call Sume Agent Completions from a webhook-triggered run. Send generation_spend_cap_usd and an Idempotency-Key on every call.

Yes. Run the Automation, and have the step that needs media POST to https://api.sume.com/v1/agent/completions with a required generation_spend_cap_usd and an Idempotency-Key, so an unattended run cannot spend past a number you chose.
Cursor Automations start from several triggers. Its docs list scheduled runs, source control events, Slack, webhooks, Linear, Sentry and PagerDuty. For a webhook, the docs say you save the automation first, which generates a webhook URL to call and an API key for authentication. Nobody is watching these runs, which is exactly the setting Sume's spend caps were built for.
Two ways to give the Automation Sume
You can connect the hosted MCP to the Automation, or call the REST API from a script. Cursor's docs advise connecting only servers you trust with the permissions the automation needs, and that is the question to answer first.
| Option | Credential | What the run can do | Spend control |
|---|---|---|---|
| Hosted MCP at mcp.sume.com/mcp | Sume API key or OAuth session | An API key session sees the full tool set, paid tools included | max_spend_usd per call when passed; wallet admission |
| REST Agent Completion | API key with agent_completions:write | Hands the whole task to the Sume agent | generation_spend_cap_usd, required, no default |
The REST call
Agent Completions return 202 with an agent.run receipt, and you poll it. The scope needed is agent_completions:write; keys created before the feature shipped lack it, and service-account keys get a 403. The Idempotency-Key makes a replayed webhook return the original receipt rather than a second run.
import json, os, urllib.request
key = os.environ["SUME_API_KEY"]
body = {
"instruction": "Make a 6 second vertical product clip from the attached brief.",
"generation_spend_cap_usd": 2,
}
req = urllib.request.Request(
"https://api.sume.com/v1/agent/completions",
data=json.dumps(body).encode(),
headers={
"Authorization": f"Bearer {key}",
"Content-Type": "application/json",
"Idempotency-Key": "automation-pr-4821-clip-1",
},
method="POST",
)
with urllib.request.urlopen(req) as res:
run = json.load(res)["data"]
print(run["id"], run["status"], run["status_url"])Run as Me or as a service account
Cursor lets an Automation run as you, billed to you, or as a team service account billed to the team's usage pool. That is Cursor's billing. On the Sume side the credential is separate: an API key you create in the dashboard. Note that a Sume service-account key cannot create Agent Completions, so use a normal key with the right scopes for this call.
Pick the idempotency key from the event, such as the pull request number, so a retried webhook cannot start a second paid run. Poll GET /v1/agent-runs/{id} until the status is completed, failed or canceled, or register a webhook on the completion; see run webhooks.
Sources
Related posts
More in Agents
- Fire a cron schedule on demand: api_trigger_enabled, cron kept
A Sume cron schedule can also accept API runs. Turn on api_trigger_enabled and your service can start it now without touching the cadence.
- Hermes Agent cron job that starts a Sume Format run
A Hermes cron job begins with no memory of last week. Write the prompt, idempotency key, spend cap and SILENT or CRON_FAILURE reply so a Sume run starts once.
- Hermes cron no-agent script: poll a Sume bulk queue quietly
A Hermes cron script that prints nothing while a Sume bulk queue runs and one line when every item is terminal. Includes the Python, 404 and 429 cases.
- HydraFusion Cascade and Critique: keep Sume paid calls from repeating
HydraFusion can draft, critique and revise a task. Put an idempotency_key on every Sume paid call so a revised pass cannot bill the same render twice.
Written by Sume