Mastra respondToToolApproval needs toolCallId: Sume paid calls
Mastra now rejects approval responses without toolCallId. When you approve a Sume paid tool call, key it to that id and keep its idempotency_key stable.

Mastra's release notes list a breaking change: session.respondToToolApproval(...) now requires toolCallId, and id-less approval responses are rejected. For a Sume paid tool call, send the approval with the id of the exact call you showed the user, and keep that call's idempotency_key unchanged if you retry.
Vendor facts are from the Mastra releases page; Sume facts from MCP tools and gates and Jobs and results, read 2026-10-01.
What changed in Mastra?
Besides the required toolCallId, the same note says related approval APIs now key gates per thread and run, and grant scoping was updated. Check your own approval code against that note; this post does not cover the rest of the release.
Is a Sume idempotency_key the same as an approval?
No. The docs describe idempotency_key as a stable key for transport and dedup, not human approval. Two ids do two jobs here.
| Id or gate | Purpose |
|---|---|
toolCallId (Mastra) | Ties an approval to one pending tool call |
idempotency_key (Sume) | Required on write and paid tools; transport and dedup |
dry_run=true | Admission and cost preview only; no job submitted |
max_spend_usd | Enforced only when provided |
How should I wire the approval?
Ask for approval before the paid call runs, using the call id Mastra gives you. Show the user a dry_run result first when the spend is large; the docs prefer generation_admission_preview and/or dry_run before expensive bursts. Write tools are marked readOnlyHint: false in the server's tool results, which is a useful flag to require approval on.
What if the approved call is retried?
Reuse the same key only for the same operation and payload. A changed payload needs a new key. If an approval times out or the connection drops, read the job state instead of submitting again; see Mastra background tasks and Sume job leases.
Sources
Related posts
More in Integrations
- OpenAI Agents Python conditional approval and Sume dry_run
Openai-agents-python v0.22.3 aligns conditional approvals with validated tool arguments. For Sume tools, base the check on tools_schema and dry_run.
- Snapchat Ads MCP and hosted Sume tools in one agent
Snap's Ads MCP server answers campaign questions and is read-only at launch. Add Sume's hosted MCP in the same agent to turn the findings into creative.
- Tavus PAL MCP connectors vs Sume hosted MCP tools and gates
Tavus MCP connectors let a PAL call third-party MCP servers. Here is what Sume's hosted MCP at mcp.sume.com exposes and the gates a paid call needs.
- VS Code 1.140 session authorization server: what Sume issues
VS Code 1.140 proposes a field naming the authorization server behind a session. For Sume, that server is the MCP origin, mcp.sume.com.
Written by Sume