Gemini CLI trust: true removes the prompt; what guards Sume spend

With trust: true, Gemini CLI stops confirming a server's tool calls. For Sume the guards left are idempotency_key, wallet admission and your max_spend_usd.

4 min readSume
All posts

In Gemini CLI, setting "trust": true on an MCP server bypasses tool call confirmations for that server; the default is false. If that server is Sume with an API key, nothing asks a human before a paid call. What remains is Sume's server-side checks: a required idempotency_key, wallet admission, and a spend cap only if you send one.

What Sume checks without a prompt

The table is from Sume's tools and gates page. The key point: the gates stop duplicates and overdraws, but none of them asks whether you wanted this render.

Gemini CLI documents the flag as a way to skip confirmation for servers you fully control. Sume is a hosted service that bills per call, so treat it as a server you trust to behave, not one whose every call you have approved. A prompt that is injected into the model through a web page or a document can still reach a trusted paid tool.

Gates on a paid Sume MCP call (Sume docs, read 2026-10-06)
GateRequired?What it does
idempotency_keyRequired on write and paid toolsDedup of retries; Sume says it is not human approval
Wallet and admissionAlwaysRefuses a call the balance or queue cannot take
dry_run=trueOptionalCost preview only, nothing is submitted
max_spend_usdOptionalEnforced only when you provide it

Options that keep a human in the loop

Leave trust at its default and let Gemini CLI confirm each paid call. Or narrow what the model can see: Gemini CLI's includeTools and excludeTools filter tools by name, and excludeTools wins when both are set. Hiding the paid generators leaves a server that can browse the catalog and read jobs but cannot spend.

Sume gives you a second, server-side way to do the same. A hosted OAuth session with only mcp:read sees read-only tools; the write and paid tools are hidden until you turn Write on at the consent page. There is no separate paid scope.

  • Trusted server plus API key: every paid tool is visible and unprompted.
  • Trusted server plus OAuth read-only: paid tools are not listed, so there is nothing to confirm.
  • Untrusted server plus API key: you confirm each call, and max_spend_usd can still cap it.

The tradeoff

Confirmations get tiresome during a long session, which is why people turn trust on. If you do, put the limit somewhere else: pass max_spend_usd on every paid call your instructions describe, and run dry_run before a burst. A wrong prompt then costs at most the cap, not the wallet.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume