OpenClaw cron tool allowlists for unattended jobs that call Sume
OpenClaw v2026.8.35 keeps explicit cron tool allowlists. Name the Sume tools a job may call, and pair them with a read-only OAuth grant or a capped key.

OpenClaw v2026.8.35 lists a fix to "retain explicit cron tool allowlists while repairing stale automatic snapshots" (release notes, read 2026-10-04). For a cron job that calls Sume, the safe setup is to list exactly the Sume tools the job may use, then enforce the same limit on Sume's side with a read-only grant or a capped call.
Two layers of limit
An allowlist in the client says which tools the job may call. A scope on the server says which tools exist for that credential. Using both means a client bug cannot widen what the job can do, and a leaked credential cannot reach tools the job never needed.
| Layer | What it limits | Set where |
|---|---|---|
| Cron tool allowlist | Tools the job may call | OpenClaw job config |
| OAuth mcp:read only | Read tools; write tools are refused | Sume consent, Write toggle off |
| max_spend_usd on a call | Spend for that call, when sent | In the tool arguments |
Pick tools by what the job does
A status report job needs only read tools, such as checking account state and job status, so grant it nothing else. A job that renders needs a write tool, and then every paid call requires idempotency_key, should send dry_run while you test it, and should send max_spend_usd so a surprise price cannot go through (MCP tools and gates).
Run tools_list once, copy the names the job needs into the allowlist, and leave out the rest.
Which credential to schedule with
Sume's OAuth access token lasts 3600 seconds and no refresh token is issued, so an unattended job running on OAuth will stop working within the hour. For a cron job use an API key, which gets the full tool set, and rely on the allowlist and the caps above to narrow it. Keep the key in the runner's secret store, and rotate it if it appears in a log.
- Read-only job: OAuth is fine for a quick test; use a key for the real schedule.
- Render job: API key, allowlisted tools,
idempotency_keyper intended output,max_spend_usdon each call. - Verify with
mcp_health, which names the credential in use.
Check the allowlist after upgrades
The fix suggests allowlists could be altered by a repair step in an earlier version. After upgrading, run the job in a test and confirm a tool outside the list is refused before you trust the schedule with a paid tool.
Sources
Related posts
More in Integrations
- Retool agent can create a REST resource: set it up for Sume
Retool's app builder agent can now create REST API resources from a prompt. Tell it the Sume base URL, one auth header and a free GET /v1/me test.
- Shopify selling_plan_id in order webhooks: a Sume welcome clip
Shopify 10.01 order webhooks carry selling_plan_id on line items. Use it to start one Sume welcome video per subscription order, with a safe retry key.
- A Supabase job table for Sume webhooks: upsert on job_id
Sume retries webhooks up to 10 times. A Postgres table keyed on job_id with ON CONFLICT turns repeat deliveries into no-ops. Schema, SQL and the order of steps.
- ubuntu-latest moves to 26.04: test your Sume workflow now
GitHub is moving ubuntu-latest to Ubuntu 26.04 between Oct 19 and Nov 19. Run a Sume API smoke test on both images, or pin 24.04, before it flips.
Written by Sume