Which workspace does a Sume MCP call spend from? Key or sign-in

The API key or the signed-in account selects the workspace; Sume tools never take a workspace id from the prompt. Confirm it with account_me before you spend.

4 min readSume
All posts

The credential decides. With an API key, the workspace is the one the key belongs to. With OAuth, it is the account that signed in on the consent page. Sume's safe-automation guidance says tools must not accept a workspace id from the user, so you cannot redirect a call by naming another workspace in a prompt. To see which one you are on, call account_me.

What picks the workspace

The rule comes from the workspace-isolation section of Safe automation: the key or the app session selects the workspace. The quickstart describes account_me as the call that confirms the workspace account context.

Workspace selection on hosted MCP (Sume docs, read 2026-10-06)
CredentialSelects the workspace byCheck it with
API keyThe key itselfaccount_me, then balance_get
OAuth sessionThe account that signed in at consentaccount_me; mcp_health shows the auth source
Prompt textNothing; tools do not take a workspace idNot applicable

A pre-flight that fits in two calls

Before an unattended agent spends, call account_me to see identity and workspace binding, then balance_get to see what that workspace can pay for. mcp_health tells you whether the session came from OAuth or an API key, which matters because OAuth read-only sessions cannot make paid calls at all.

Spend is then bounded by the wallet and admission rules. An optional max_spend_usd on a call sets a cap only when you pass it, and dry_run previews a cost without submitting.

  • Do not store several keys in one agent and let the prompt choose between them.
  • If an agent seems to be spending from the wrong place, look at which credential it sent, not at the prompt.
  • Rotate any key that appeared in a log or chat history.

The tradeoff

Binding the workspace to the credential keeps a prompt injection from steering spend into another workspace, but it also means that working across workspaces needs separate connections, with separate keys or sign-ins. That is more setup for agencies. The docs allow one exception, a product that explicitly supports switching, and they do not list one for hosted MCP, so plan for one connection per workspace.

If you are unsure which workspace a running agent is using, do not guess from the prompt. Ask it to call account_me and report the answer back, and stop it before any paid call if the answer is not the workspace you expected. That check costs nothing, because it is a read.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume