Pydantic AI ToolCallJudge: check a Sume paid call before it runs
Pydantic AI 2.53.0 adds ToolCallJudge to assess tool calls before execution. Pair it with Sume's dry_run and max_spend_usd on paid calls.

Add ToolCallJudge from Pydantic AI v2.53.0 (2026-10-02) in front of Sume's paid tools and make the judge check that the call carries a spend ceiling. The release describes it as a way to assess tool calls before execution, which is the right place to catch a missing max_spend_usd.
The judge reduces mistakes; it is not a guarantee, so Sume's own checks stay in the loop.
What 2.53.0 includes
The release adds ToolCallJudge, an AskUser capability that defers to the host with a timeout, and managed subagents in CLAI2.
At a glance
| Check | Enforced by |
|---|---|
| idempotency_key present | Sume server (required) |
| max_spend_usd set | Your judge or policy (optional in Sume) |
| dry_run reviewed | Your workflow |
| Scope mcp:write granted | Sume OAuth consent |
What the judge should look for
For Sume, the useful checks are mechanical: the call has an idempotency_key, max_spend_usd is set and within your budget, and dry_run was used first for anything new. Sume will reject a write or paid call that lacks idempotency_key, but it does not require the ceiling.
Wire the Sume server as an MCP toolset, then let the judge see the tool name and arguments.
- Reject paid calls without max_spend_usd.
- Allow read tools without review.
- Use AskUser for anything the judge flags.
Limits and what is not verified
I did not run ToolCallJudge against a live Sume server, and the release notes do not describe the judge's interface in detail. Use Pydantic AI's docs for the code.
Sources
Related posts
More in Developers
- Pydantic AI cancel_and_resume vs Sume agent run cancel
Pydantic AI 2.54.0 shows cancel_and_resume. Sume Agent Completions have a different cancel: a run is cancelled by id and resumes only as a new run.
- Pydantic model to Sume output_schema: extra forbid, no defaults
Turn a Pydantic v2 model into a valid Sume Format output_schema: extra=forbid, nullable instead of defaults, and the SumeMediaFile reference. Tested.
- Unit test Sume webhook signature checks in pytest (Python)
A pytest file for HMAC webhook verification: tamper, rotation header, stale timestamp and empty secret, written against Sume's sume-v1 scheme.
- Python 3.14.8 Agent Completions: spend cap, schema, asyncio.run
Start an Agent Completion from Python 3.14.8 with asyncio.run, a required generation_spend_cap_usd, an output_schema and an Idempotency-Key, then poll the run.
Written by Sume