Roo Code alwaysAllow for Sume MCP: which tools to auto-approve

Roo Code alwaysAllow skips the approval click. Auto-approve Sume read tools only, and keep paid ones manual or behind dry_run and a spend cap.

5 min readSume
All posts

Put Sume's read tools in alwaysAllow and leave the paid ones out. Roo auto-approves any tool named there, with no prompt. Sume's own gates are idempotency_key for writes and paid calls, plus optional dry_run and max_spend_usd. Those gates deduplicate and preview; none of them replaces a human clicking approve on spend.

Auto-approve split for Sume tools, read 2026-10-08
GroupExamplesalwaysAllow?
Discoverymcp_health, tools_list, tools_schemaYes
Readsjobs_status, jobs_wait, jobs_result, assets_getYes
Previewgeneration_admission_previewYes
Paidgenerate_image, generate_video, avatars_createNo
Writejobs_cancel, assets_createNo

Entry

The list names are the live underscore tool ids from tools_list.

{
  "mcpServers": {
    "sume": {
      "type": "streamable-http",
      "url": "https://mcp.sume.com/mcp",
      "alwaysAllow": [
        "mcp_health", "tools_list", "tools_schema",
        "jobs_status", "jobs_wait", "jobs_result",
        "generation_admission_preview"
      ]
    }
  }
}

Why paid stays manual

The Sume docs state that idempotency_key is a stable key for transport and dedup, not human approval. dry_run=true previews cost without submitting. max_spend_usd is enforced only if you pass it. There is no mcp:paid scope, so under an API key every paid tool is callable.

Tighter options

Use OAuth with Write off and the paid tools are hidden from the session entirely. You can also list tool names in disabledTools to hide them from Roo. Together these are stronger than approval habits.

  • OAuth read-only: write and paid tools return insufficient_scope.
  • disabledTools: Roo never offers the named tools.
  • dry_run first, then the real call with a new idempotency_key.
  • Add max_spend_usd when you want a ceiling.

How to review the list

Treat alwaysAllow like a permissions file. Review it when you add a tool and when Sume's tool list changes. Compare it with tools_list output under the credential you use, since an OAuth read-only session shows fewer tools than an API-key session.

A sensible default

Auto-approve discovery, reads and the preview. Approve every paid call by hand until the workflow is stable, and then add a cap with max_spend_usd in the prompt rather than loosening approval. A cap is enforced by Sume only when the argument is present, so make it part of the agent's standing instructions.

There is a subtle point about jobs_wait: it is a read, so auto-approving it is safe, but it can hold a call for up to 55 seconds. That is fine for an agent that is watching a job, and it means an auto-approved loop can run for a long time if the agent keeps waiting. Ask the agent to report progress after each slice, so you see when a job is stuck rather than slow. A human who sees the same job still queued after several slices can cancel it.

Keep in mind that Sume's hosted endpoint is the same for every client in this series: https://mcp.sume.com/mcp, with OAuth consent on the MCP host or an API key in a header. What differs is each client's config keys, its timeout defaults and its approval prompts. When a connection misbehaves, first separate those two layers: test the endpoint with curl and your credential, and only then look at the client's settings.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume