Who authorizes agent spend on Sume: mcp:write, key and balance

On Sume, spend is authorized by the token: mcp:read hides paid tools, mcp:write allows them, and an API key sees all. There is no mcp:paid scope.

4 min readSume
All posts

On Sume the credential decides whether an agent can spend. A token with only mcp:read cannot see or call paid tools. A token with mcp:write, or an API key, can, and each paid call still needs an idempotency_key. Sume has no separate mcp:paid scope (tools and gates).

The AAIF essay Who told the agent it could spend? argues that under the 2026-07-28 MCP draft, authorization stops being a login detail and becomes where financial risk is actually controlled. That matches how Sume is built, so it is worth walking through.

The control points

Spend control layers (read 2026-10-04)
LayerWhat it decidesWhere documented
OAuth scope mcp:readRequired; read-only; write and paid tools hiddenSume OAuth docs
OAuth scope mcp:writeOpt-in on the consent page; unlocks write and paid toolsSume OAuth docs
API keySees the full tool setSume tools and gates
idempotency_keyRequired on paid and write callsSume tools and gates
max_spend_usd, dry_runOptional cap and previewSume tools and gates
AAIF framingRequest flow: pricing returned, wallet approves, agent retries with proofAAIF essay

What the user actually agrees to

The consent page is the human decision point. A person who ticks mcp:write is handing the agent the ability to start paid jobs from their balance, so word your own app's prompt to say so. If you want an unattended agent, use an API key instead and move the decision to key creation, where you can choose how many keys exist and rotate them.

Calling a hidden tool anyway returns insufficient_scope rather than a silent no-op, which makes the failure easy to spot in logs.

Practical setup

  • Default new connections to mcp:read and ask for mcp:write only when a task needs it.
  • Send max_spend_usd on every paid call.
  • Keep paid calls behind your client's approval step.
  • Use separate keys for separate agents so one can be revoked alone.

Sources

Related posts

More in Agents

All Agents posts

Written by Sume