max_spend_usd is optional on Sume MCP: send it on every paid call
Sume enforces max_spend_usd only when you send it. Make your coding agent send it with dry_run and an idempotency_key. Wallet admission is the real gate.

On Sume's hosted MCP server, max_spend_usd is optional, and Sume enforces it only when you provide it. A coding agent that omits it has no per-call ceiling beyond wallet admission, so tell your agent to send it on every paid call, together with dry_run for a preview and an idempotency_key, which is required.
The gates, one by one
The gates table in the MCP docs is short, and each row is different. idempotency_key is required on write and paid tools, and it is a transport and de-duplication key, not human approval. dry_run=true is an optional admission and cost preview that does not submit the job. max_spend_usd is optional and enforced only when supplied. The legacy allow_write and allow_paid flags are accepted for compatibility, are not required, and cannot bypass a missing mcp:write scope.
| Gate | Required? | What it does |
|---|---|---|
| idempotency_key | Yes, on write and paid tools | Dedupes a retry; not an approval |
| dry_run=true | No | Previews admission and cost; submits nothing |
| max_spend_usd | No, enforced only if sent | A ceiling for that call |
| allow_write, allow_paid | No, legacy | Accepted; cannot bypass a missing scope |
What really stops a paid call
The docs are direct about the spend gate: spend is wallet and admission, and there is no mcp:paid scope. Under OAuth with only mcp:read, the write and paid tools are hidden and return insufficient_scope. With mcp:write, or with an API key, the full tool set is available, and a paid submit still needs its key and admission.
Put the habit in the agent's instructions
That makes the optional gates a client-side habit. The docs recommend generation_admission_preview or dry_run before expensive bursts, and say that a normal single create does not need them. So write the habit into your agent's standing instructions, and keep the numbers small.
A standing instruction
A standing instruction like the one below works in a project file that your agent reads at the start of a session. Edit the amount to match your own limit.
Sume paid tools (generate_video, generate_image, music_create, tts_create,
avatars_create, avatar-videos_create):
1. Call tools_schema for the tool first.
2. Run it once with dry_run=true and show me the cost.
3. Submit only after I say go, with a fresh idempotency_key and
max_spend_usd set to the previewed cost plus 20 percent.
4. If jobs_wait returns wait_slice_expired, call jobs_wait again on the
same job id. Never call the create tool a second time.Why the last line is there
Step 4 matters as much as the cap. The remote jobs_wait hold is 50 seconds by default, with a cap of 55, and a slice that expires is not a failure. The job is still running, so a second create would pay twice.
Short version
Set the ceiling on every paid request, preview anything large, and keep the idempotency key stable for each retry.
Sources
Related posts
More in Developers
- MCP 2026 roadmap lists audit trails: what Sume records for agents
The MCP 2026 roadmap names audit trails as an enterprise priority. Here is what Sume records for an agent's paid work today: jobs, receipts, the usage ledger.
- RFC 9207 iss validation in the 2026-07-28 MCP spec, and Sume OAuth
The 2026-07-28 MCP spec adds RFC 9207 iss validation (SEP-2468). Sume's OAuth issuer is the MCP origin, so a client should expect mcp.sume.com and nothing else.
- MCP SEP-2352: credentials bound to issuer, re-register on a new host
MCP SEP-2352 binds client credentials to the issuer and deprecates DCR for Client ID Metadata Documents. Re-register if the Sume host changes.
- MCP subscriptions/listen and tasks versus Sume's pull-based job events
The 2026-07-28 MCP spec adds subscriptions/listen and a tasks extension. Sume has no SSE or WebSocket: poll job events, or use jobs_wait with a 55-second cap.
Written by Sume