Gemini CLI v0.63 plan execution in CI: gate paid Sume calls first
Gemini CLI preview v0.63.0 adds autonomous plan execution in non-interactive mode. Before unattended runs, gate Sume paid tools with dry_run and max_spend_usd.

When a CLI agent can execute a plan on its own with nobody watching, the safeguards have to live in the tool arguments and the credential. Gemini CLI's preview v0.63.0 adds autonomous plan execution in non-interactive mode, so a CI job that renders marketing assets should combine a read-only first pass with dry_run and max_spend_usd on the paid step.
The release page lists stable v0.62.0, preview v0.63.0 and a nightly v0.64.0 dated 2026-10-03.
Three levels of the Gemini CLI release channels
Because plan execution is in the preview channel, treat it as a build you test, not one you hand a production key.
| Channel | Version | Relevant change |
|---|---|---|
| Stable | v0.62.0 | Current stable build. |
| Preview | v0.63.0 | Autonomous plan execution in non-interactive mode. |
| Nightly | v0.64.0 (2026-10-03) | Next build; not described further on the page. |
Use scope as the first gate
Sume's hosted MCP separates visibility by credential. An OAuth session with mcp:read sees only read-only tools. Mutating and paid tools such as generate_image are hidden until the session has mcp:write, and a call to one returns insufficient_scope. An API key sees the full set.
For a CI job, that suggests two stages. Plan with a read-only credential, review the plan, and only then run a stage that holds a write-capable credential.
Use arguments as the second gate
Paid and write tools require an idempotency_key. The optional fields do the safety work.
dry_run=truepreviews admission and cost without submitting a job.max_spend_usdis enforced only when you provide it, so provide it.generation_admission_previewreports balance and queue behaviour before a burst.- A stable key per planned step means a retried step returns the original job instead of billing twice.
A plan-step contract
Give the agent a plan format where each paid step carries its own cap and key. A step might read: tool generate_image, key launch-hero-001, dry_run true, max_spend_usd 2. The first run previews. A second run, approved by a person or a policy, repeats the step with dry_run false.
The docs say ordinary single creates do not need admission theater, but expensive bursts do. A plan that fans out many calls is a burst.
After the plan runs
Plan execution ends when the agent stops, not when the render finishes. Jobs are durable, so have the pipeline record job ids and read results later.
- Use
jobs_waitwith batches of up to 20 ids; each call holds at most 55 seconds. - On
wait_slice_expired, repeat the wait with the same ids rather than resubmitting. - Read
jobs_resultfor completed jobs and keep themedia.sume.comURLs. - Fail the CI step if a job is
failedorcanceled, and log the request id.
Sources
Related posts
More in Developers
- Google's June 15 deprecation notice gave 15 and 63 days: run a drill
Google announced Veo and Imagen 4 deprecations on Jun 15, 2026 with shutdowns Jun 30 and Aug 17. Here is a five-step drill that fits inside the shorter window.
- Grok Imagine video API: 15 s, 5 references, request-ID polling
xAI's video guide for grok-imagine-video-1.5 lists up to 15 seconds, up to 5 reference images and async polling by request ID. The same loop on Sume jobs.
- How long AI video vendors keep your file: Veo 2 days, Higgsfield 7+
Veo keeps videos two days, Higgsfield files at least seven, Sora Batch outputs were kept 24 hours. Retention facts and a download-on-complete script.
- How to get an AI video generation API key: Sume steps and gotchas
Create a workspace API key in the Sume dashboard, send it as one header, check it with GET /v1/me, and keep it on your server. Scopes are fixed at creation.
Written by Sume