OpenAI Agents SDK MCP tool_input_guardrails for Sume spend

tool_input_guardrails on an Agents SDK MCP server can reject a call before it runs. For Sume paid tools, check idempotency_key and max_spend_usd.

4 min readSume
All posts

tool_input_guardrails is a list you pass to an Agents SDK MCP server object. Each guardrail reads the tool arguments and either allows the call or rejects it with a message. For Sume's paid tools you can use one to refuse any call that lacks idempotency_key or max_spend_usd, before the request leaves your process.

The SDK behavior is from OpenAI's MCP page. The gate fields are from Sume's MCP tools and gates, both read 2026-09-30.

Which MCP objects accept tool_input_guardrails?

The page says the setting applies only to tools exposed by local MCP server objects such as MCPServerStdio, MCPServerSse and MCPServerStreamableHttp. It does not add client-side guardrails to HostedMCPTool, which the Responses API executes as a hosted tool. So a guardrail on a hosted tool will not run.

What does Sume require on a paid call?

Three gate fields matter. Only the first is required.

Sume gate fields, from the docs read 2026-09-30
FieldRequired?Meaning in the docs
idempotency_keyRequired on write and paid toolsStable key for transport/dedup, not human approval
dry_run=trueOptionalAdmission/cost preview only; do not submit the job
max_spend_usdOptionalEnforced only when provided

What does a guardrail for these look like?

Same shape as OpenAI's example, which rejects arguments containing a secret. Here it requires a spend cap. It only checks arguments, and as written it runs for every tool on that server, so read tools without these fields would be rejected too. Attach it to a server used only for paid calls, or branch on the tool name your SDK version exposes.

import json
from agents import ToolGuardrailFunctionOutput
from agents.decorators import tool_input_guardrail

@tool_input_guardrail
def require_spend_cap(data):
    args = json.loads(data.context.tool_arguments or "{}")
    if "max_spend_usd" not in args or "idempotency_key" not in args:
        return ToolGuardrailFunctionOutput.reject_content(
            "Add idempotency_key and max_spend_usd before a paid Sume call."
        )
    return ToolGuardrailFunctionOutput.allow()

Is a guardrail the same as approval?

No. The Sume docs say idempotency_key is for transport and dedup, not human approval. A guardrail checks arguments; approval is a separate step. For the approval side see Vercel AI SDK tool approval for paid video.

Connect the server at https://mcp.sume.com/mcp, as in the quickstart.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume