max_spend_usd is optional on Sume MCP: send it on every paid call

Sume enforces max_spend_usd only when you send it. Make your coding agent send it with dry_run and an idempotency_key. Wallet admission is the real gate.

4 min readSume
All posts

On Sume's hosted MCP server, max_spend_usd is optional, and Sume enforces it only when you provide it. A coding agent that omits it has no per-call ceiling beyond wallet admission, so tell your agent to send it on every paid call, together with dry_run for a preview and an idempotency_key, which is required.

The gates, one by one

The gates table in the MCP docs is short, and each row is different. idempotency_key is required on write and paid tools, and it is a transport and de-duplication key, not human approval. dry_run=true is an optional admission and cost preview that does not submit the job. max_spend_usd is optional and enforced only when supplied. The legacy allow_write and allow_paid flags are accepted for compatibility, are not required, and cannot bypass a missing mcp:write scope.

Safety gates on the hosted MCP server, from docs.sume.com/mcp/tools-and-gates (read 2026-10-05)
GateRequired?What it does
idempotency_keyYes, on write and paid toolsDedupes a retry; not an approval
dry_run=trueNoPreviews admission and cost; submits nothing
max_spend_usdNo, enforced only if sentA ceiling for that call
allow_write, allow_paidNo, legacyAccepted; cannot bypass a missing scope

What really stops a paid call

The docs are direct about the spend gate: spend is wallet and admission, and there is no mcp:paid scope. Under OAuth with only mcp:read, the write and paid tools are hidden and return insufficient_scope. With mcp:write, or with an API key, the full tool set is available, and a paid submit still needs its key and admission.

Put the habit in the agent's instructions

That makes the optional gates a client-side habit. The docs recommend generation_admission_preview or dry_run before expensive bursts, and say that a normal single create does not need them. So write the habit into your agent's standing instructions, and keep the numbers small.

A standing instruction

A standing instruction like the one below works in a project file that your agent reads at the start of a session. Edit the amount to match your own limit.

Sume paid tools (generate_video, generate_image, music_create, tts_create,
avatars_create, avatar-videos_create):
1. Call tools_schema for the tool first.
2. Run it once with dry_run=true and show me the cost.
3. Submit only after I say go, with a fresh idempotency_key and
   max_spend_usd set to the previewed cost plus 20 percent.
4. If jobs_wait returns wait_slice_expired, call jobs_wait again on the
   same job id. Never call the create tool a second time.

Why the last line is there

Step 4 matters as much as the cap. The remote jobs_wait hold is 50 seconds by default, with a cap of 55, and a slice that expires is not a failure. The job is still running, so a second create would pay twice.

Short version

Set the ceiling on every paid request, preview anything large, and keep the idempotency key stable for each retry.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume