OpenClaw cron tool allowlists for unattended jobs that call Sume

OpenClaw v2026.8.35 keeps explicit cron tool allowlists. Name the Sume tools a job may call, and pair them with a read-only OAuth grant or a capped key.

5 min readSume
All posts

OpenClaw v2026.8.35 lists a fix to "retain explicit cron tool allowlists while repairing stale automatic snapshots" (release notes, read 2026-10-04). For a cron job that calls Sume, the safe setup is to list exactly the Sume tools the job may use, then enforce the same limit on Sume's side with a read-only grant or a capped call.

Two layers of limit

An allowlist in the client says which tools the job may call. A scope on the server says which tools exist for that credential. Using both means a client bug cannot widen what the job can do, and a leaked credential cannot reach tools the job never needed.

Where each limit is enforced. Sources: OpenClaw release notes and Sume docs, read 2026-10-04.
LayerWhat it limitsSet where
Cron tool allowlistTools the job may callOpenClaw job config
OAuth mcp:read onlyRead tools; write tools are refusedSume consent, Write toggle off
max_spend_usd on a callSpend for that call, when sentIn the tool arguments

Pick tools by what the job does

A status report job needs only read tools, such as checking account state and job status, so grant it nothing else. A job that renders needs a write tool, and then every paid call requires idempotency_key, should send dry_run while you test it, and should send max_spend_usd so a surprise price cannot go through (MCP tools and gates).

Run tools_list once, copy the names the job needs into the allowlist, and leave out the rest.

Which credential to schedule with

Sume's OAuth access token lasts 3600 seconds and no refresh token is issued, so an unattended job running on OAuth will stop working within the hour. For a cron job use an API key, which gets the full tool set, and rely on the allowlist and the caps above to narrow it. Keep the key in the runner's secret store, and rotate it if it appears in a log.

  • Read-only job: OAuth is fine for a quick test; use a key for the real schedule.
  • Render job: API key, allowlisted tools, idempotency_key per intended output, max_spend_usd on each call.
  • Verify with mcp_health, which names the credential in use.

Check the allowlist after upgrades

The fix suggests allowlists could be altered by a repair step in an earlier version. After upgrading, run the job in a test and confirm a tool outside the list is refused before you trust the schedule with a paid tool.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume