Which workspace does a Sume MCP call spend from? Key or sign-in
The API key or the signed-in account selects the workspace; Sume tools never take a workspace id from the prompt. Confirm it with account_me before you spend.

The credential decides. With an API key, the workspace is the one the key belongs to. With OAuth, it is the account that signed in on the consent page. Sume's safe-automation guidance says tools must not accept a workspace id from the user, so you cannot redirect a call by naming another workspace in a prompt. To see which one you are on, call account_me.
What picks the workspace
The rule comes from the workspace-isolation section of Safe automation: the key or the app session selects the workspace. The quickstart describes account_me as the call that confirms the workspace account context.
| Credential | Selects the workspace by | Check it with |
|---|---|---|
| API key | The key itself | account_me, then balance_get |
| OAuth session | The account that signed in at consent | account_me; mcp_health shows the auth source |
| Prompt text | Nothing; tools do not take a workspace id | Not applicable |
A pre-flight that fits in two calls
Before an unattended agent spends, call account_me to see identity and workspace binding, then balance_get to see what that workspace can pay for. mcp_health tells you whether the session came from OAuth or an API key, which matters because OAuth read-only sessions cannot make paid calls at all.
Spend is then bounded by the wallet and admission rules. An optional max_spend_usd on a call sets a cap only when you pass it, and dry_run previews a cost without submitting.
- Do not store several keys in one agent and let the prompt choose between them.
- If an agent seems to be spending from the wrong place, look at which credential it sent, not at the prompt.
- Rotate any key that appeared in a log or chat history.
The tradeoff
Binding the workspace to the credential keeps a prompt injection from steering spend into another workspace, but it also means that working across workspaces needs separate connections, with separate keys or sign-ins. That is more setup for agencies. The docs allow one exception, a product that explicitly supports switching, and they do not list one for hosted MCP, so plan for one connection per workspace.
If you are unsure which workspace a running agent is using, do not guess from the prompt. Ask it to call account_me and report the answer back, and stop it before any paid call if the answer is not the workspace you expected. That check costs nothing, because it is a read.
Sources
Related posts
More in Developers
- Word timestamps to video frame numbers at 29.97 fps in Python
Sume STT words[] carry start and end in seconds. Convert them to frame indexes with exact 30000/1001 math so cuts do not drift on long timelines.
- Workers OAuth Provider v1 or Sume's hosted MCP: which do I need?
Cloudflare's v1 OAuth library is for building your own MCP server. To call Sume tools from Claude or Cursor, connect Sume's hosted endpoint and skip the build.
- x-sume-webhook-timestamp is Unix seconds: the Date.now() mistake
Sume's x-sume-webhook-timestamp is Unix seconds. Comparing it to Date.now() in Node is off by 1000 and rejects every delivery. A short, tested fix.
- YouTube thumbnail test set: n=4 on GPT Image 2.5 high may return 202
Four 1280x720 thumbnail takes cost $0.1425 on GPT Image 2.5 high via Sume, and a slow call can return 202 instead of 200. A Python client that handles both.
Written by Sume