Gemini CLI trust: true removes the prompt; what guards Sume spend
With trust: true, Gemini CLI stops confirming a server's tool calls. For Sume the guards left are idempotency_key, wallet admission and your max_spend_usd.

In Gemini CLI, setting "trust": true on an MCP server bypasses tool call confirmations for that server; the default is false. If that server is Sume with an API key, nothing asks a human before a paid call. What remains is Sume's server-side checks: a required idempotency_key, wallet admission, and a spend cap only if you send one.
What Sume checks without a prompt
The table is from Sume's tools and gates page. The key point: the gates stop duplicates and overdraws, but none of them asks whether you wanted this render.
Gemini CLI documents the flag as a way to skip confirmation for servers you fully control. Sume is a hosted service that bills per call, so treat it as a server you trust to behave, not one whose every call you have approved. A prompt that is injected into the model through a web page or a document can still reach a trusted paid tool.
| Gate | Required? | What it does |
|---|---|---|
| idempotency_key | Required on write and paid tools | Dedup of retries; Sume says it is not human approval |
| Wallet and admission | Always | Refuses a call the balance or queue cannot take |
| dry_run=true | Optional | Cost preview only, nothing is submitted |
| max_spend_usd | Optional | Enforced only when you provide it |
Options that keep a human in the loop
Leave trust at its default and let Gemini CLI confirm each paid call. Or narrow what the model can see: Gemini CLI's includeTools and excludeTools filter tools by name, and excludeTools wins when both are set. Hiding the paid generators leaves a server that can browse the catalog and read jobs but cannot spend.
Sume gives you a second, server-side way to do the same. A hosted OAuth session with only mcp:read sees read-only tools; the write and paid tools are hidden until you turn Write on at the consent page. There is no separate paid scope.
- Trusted server plus API key: every paid tool is visible and unprompted.
- Trusted server plus OAuth read-only: paid tools are not listed, so there is nothing to confirm.
- Untrusted server plus API key: you confirm each call, and
max_spend_usdcan still cap it.
The tradeoff
Confirmations get tiresome during a long session, which is why people turn trust on. If you do, put the limit somewhere else: pass max_spend_usd on every paid call your instructions describe, and run dry_run before a burst. A wrong prompt then costs at most the cap, not the wallet.
Sources
Related posts
More in Integrations
- GitHub Actions repository variable for the image model id: no commit
Keep the Sume image model id in a GitHub Actions repository variable, so a gpt-image-1 replacement is a settings change or one gh command, not a pull request.
- Haystack MCPTool with StreamableHttpServerInfo and Sume MCP
Connect Haystack to Sume's hosted MCP with MCPTool and StreamableHttpServerInfo: a url, an Authorization header, one tool per MCPTool, and what to call first.
- Intercom outbound message with a Sume avatar clip: email or in-app
Intercom's create-message API sends in_app, email or whatsapp with an HTML or plain body. It documents no video field, so link a Sume clip. How to set it up.
- jobs_wait for 20 transcription jobs in one MCP call
The hosted MCP jobs_wait takes up to 20 job_ids, wait_for all or any, and include_results returns each finished transcript. Retry slices of 55 seconds.
Written by Sume