MCP wants a human in the loop: Sume gates for unattended agents

MCP says a human SHOULD be able to deny tool calls. For unattended agents, Sume adds scopes, idempotency keys and a required Agent Completions cap.

4 min readSume
All posts

The MCP 2025-11-25 tools page says that for trust and safety there SHOULD always be a human in the loop with the ability to deny tool invocations, and that clients SHOULD show confirmation prompts. A scheduled or CI agent has no one at the keyboard, so the prompt is gone. What is left is what the server enforces, and for Sume that is scope, a retry key and, on one surface, a required spend cap.

What the spec asks of clients

Clients SHOULD make exposed tools clear, show indicators when tools run, and prompt for confirmation on operations. It also tells clients to show tool inputs before calling and to log tool usage for audit. None of that exists in an unattended run unless you build it.

What Sume enforces without a person

OAuth mcp:read hides write and paid tools; calls return insufficient_scope. Write and paid calls need an idempotency_key, which is dedup, not approval. max_spend_usd is optional and enforced only when you send it. API-key sessions see all tools.

Agent Completions is stricter. The docs say an interactive spend-approval prompt protects the chat UI, a backend caller does not get one, and so generation_spend_cap_usd is required with no default. The cap replaces the prompt.

Replacing the prompt, read 2026-10-07
SurfaceHuman promptServer-side stand-in
Hosted MCP, OAuthClient's own promptmcp:read default, Write toggle
Hosted MCP, API keyNoneidempotency_key; optional max_spend_usd
Agent CompletionsNoneRequired generation_spend_cap_usd
Scheduled runNoneSchedule cap, $1.00 if unset

What to add yourself

Run unattended jobs on the narrowest surface: read-only OAuth for look-ups, Agent Completions with a cap for work that spends. Send max_spend_usd on every paid MCP call. Log request ids, never signed URLs or keys.

Sources

Related posts

More in Agents

All Agents posts

Written by Sume