Goose 1.52 recipe consent before extensions: a Sume MCP recipe
Goose 1.52 asks for recipe consent before session/new spawns extensions, and caps recipe size. What to put in a recipe that uses Sume's MCP server.

A Goose recipe that wires Sume's MCP server will now ask for consent before a new session spawns its extensions, as of Goose v1.52.0 (2026-09-23). The release also sets recipe limits of 32 parameters, 200 select options and 128 KiB, which a Sume recipe stays well inside.
Put the endpoint and the spend guard in the recipe, and leave credentials out of it.
What changed
The consent step means a shared recipe cannot silently launch an extension. Reviewers see the extension list before it starts, which is the right moment to check the Sume URL.
At a glance
| Limit | Value |
|---|---|
| Parameters | 32 maximum |
| Select options | 200 maximum |
| Recipe size | 128 KiB maximum |
| Extension spawn | Needs recipe consent |
What a Sume recipe should contain
The extension is a remote streamable HTTP server at https://mcp.sume.com/mcp. Authentication should come from the user's own sign-in or API key, never from text in the recipe.
Instructions inside the recipe should tell the agent to pass an idempotency_key on every write or paid call and to set max_spend_usd, since the server enforces the key but the ceiling is optional.
- Name the single endpoint in the extension block.
- Add parameters for the spend ceiling instead of hardcoding it.
- Keep the recipe under the size limits, with room to spare.
Limits and what is not verified
The release notes do not show the consent dialog, and I did not build a recipe for this post. Check the dialog wording in your Goose version.
Sources
Related posts
More in Developers
- got maxRetryAfter and 429: rate_limited vs queue_full on Sume
got retries 429 and honors Retry-After up to maxRetryAfter. Sume sends 429 for rate_limited and for queue_full, which need different waits. Here is the split.
- got does not retry POST by default: enable it safely with Sume
got retries GET, PUT and DELETE but not POST. To retry a Sume paid submit, add POST to retry.methods and send one Idempotency-Key reused on every attempt.
- GPT-6.1 Sol rate limits (Tier 1: 500 RPM) vs a Sume bulk run window
OpenAI lists GPT-6.1 Sol limits from 500 RPM at Tier 1 to 15,000 RPM at Tier 5. A Sume bulk run uses a concurrency window of 1-16 and 100 items.
- GPT Image 2.5 cost per image by quality: the token math on Sume
Sume's docs: GPT Image 2.5 output is $30 per 1M tokens. At 1024x1024, xhigh is $0.09366 and max is $0.21072, before input tokens and Sume pricing.
Written by Sume