Goose 1.52 recipe consent before extensions: a Sume MCP recipe

Goose 1.52 asks for recipe consent before session/new spawns extensions, and caps recipe size. What to put in a recipe that uses Sume's MCP server.

5 min readSume
All posts

A Goose recipe that wires Sume's MCP server will now ask for consent before a new session spawns its extensions, as of Goose v1.52.0 (2026-09-23). The release also sets recipe limits of 32 parameters, 200 select options and 128 KiB, which a Sume recipe stays well inside.

Put the endpoint and the spend guard in the recipe, and leave credentials out of it.

What changed

The consent step means a shared recipe cannot silently launch an extension. Reviewers see the extension list before it starts, which is the right moment to check the Sume URL.

At a glance

Goose 1.52 recipe limits, read 2026-10-03.
LimitValue
Parameters32 maximum
Select options200 maximum
Recipe size128 KiB maximum
Extension spawnNeeds recipe consent

What a Sume recipe should contain

The extension is a remote streamable HTTP server at https://mcp.sume.com/mcp. Authentication should come from the user's own sign-in or API key, never from text in the recipe.

Instructions inside the recipe should tell the agent to pass an idempotency_key on every write or paid call and to set max_spend_usd, since the server enforces the key but the ceiling is optional.

  • Name the single endpoint in the extension block.
  • Add parameters for the spend ceiling instead of hardcoding it.
  • Keep the recipe under the size limits, with room to spare.

Limits and what is not verified

The release notes do not show the consent dialog, and I did not build a recipe for this post. Check the dialog wording in your Goose version.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume