Who authorizes agent spend on Sume: mcp:write, key and balance
On Sume, spend is authorized by the token: mcp:read hides paid tools, mcp:write allows them, and an API key sees all. There is no mcp:paid scope.

On Sume the credential decides whether an agent can spend. A token with only mcp:read cannot see or call paid tools. A token with mcp:write, or an API key, can, and each paid call still needs an idempotency_key. Sume has no separate mcp:paid scope (tools and gates).
The AAIF essay Who told the agent it could spend? argues that under the 2026-07-28 MCP draft, authorization stops being a login detail and becomes where financial risk is actually controlled. That matches how Sume is built, so it is worth walking through.
The control points
| Layer | What it decides | Where documented |
|---|---|---|
OAuth scope mcp:read | Required; read-only; write and paid tools hidden | Sume OAuth docs |
OAuth scope mcp:write | Opt-in on the consent page; unlocks write and paid tools | Sume OAuth docs |
| API key | Sees the full tool set | Sume tools and gates |
idempotency_key | Required on paid and write calls | Sume tools and gates |
max_spend_usd, dry_run | Optional cap and preview | Sume tools and gates |
| AAIF framing | Request flow: pricing returned, wallet approves, agent retries with proof | AAIF essay |
What the user actually agrees to
The consent page is the human decision point. A person who ticks mcp:write is handing the agent the ability to start paid jobs from their balance, so word your own app's prompt to say so. If you want an unattended agent, use an API key instead and move the decision to key creation, where you can choose how many keys exist and rotate them.
Calling a hidden tool anyway returns insufficient_scope rather than a silent no-op, which makes the failure easy to spot in logs.
Practical setup
- Default new connections to
mcp:readand ask formcp:writeonly when a task needs it. - Send
max_spend_usdon every paid call. - Keep paid calls behind your client's approval step.
- Use separate keys for separate agents so one can be revoked alone.
Sources
Related posts
More in Agents
- x402 upto vs exact: how each maps to a Sume spend cap
Apify's x402 upto charges actual usage up to an allowance; exact takes a fixed $1.00 deposit and refunds the rest. Sume's analogue is a per-call spend cap.
- 200 from an Action run call: replay or skipped? Read the receipt
A 200 on POST /v1/actions/:id/runs means an idempotency replay or a skipped run. Branch on status, idempotency_hit and skip_reason, not on the HTTP code.
- 402 automation_generation_spend_cap_exceeded in a scheduled run
The per-run generation cap rejected one job before it reserved credits. Only that job fails; the run is not canceled. Raise the cap or trim the plan.
- Agent Completion or three API calls for a render-trim-caption chain
If the steps are fixed, call the endpoints. If the task changes on every call, an Agent Completion with a required spend cap fits. How the two compare.
Written by Sume