Zed ask_user forms: confirm a Sume estimate before paying

Zed's ask_user tool lets agents ask with forms. Use it as a spend checkpoint with Sume's dry_run preview, so people approve a number, not a tool name.

5 min readSume
All posts

Zed's ask_user tool, added in 1.20.1 on 2026-09-16, lets agents ask questions through forms with selectable options, free-text input, or both (read 2026-10-03). That is a good place to put a spend confirmation for Sume: have the agent call a paid tool with dry_run=true, show the estimate in the form, and submit only when the person picks yes. The form turns a vague permission into a specific number the person has actually seen.

The Zed detail is on the stable releases page. The Sume gates are documented in MCP tools and gates, and the preview mechanics in Generation admission. For connecting Zed to Sume in the first place, see the Zed MCP server post.

Why a form beats a permission dialog

A tool-permission dialog asks, may the agent call generate_video? That is a question about the tool, and the answer is the same whether the call costs a few cents or a lot. An ask_user form can carry the estimate, the model the router picked, and a choice such as approve, change the prompt, or stop. Those options matter, because the third one saves a wasted job when the preview shows a long clip priced higher than you expected.

Permission dialog vs ask_user form, read 2026-10-03
PropertyTool permission dialogask_user form
Question askedMay this tool runDo you accept this estimate
OptionsAllow or denySelectable options, free text, or both
Carries a numberRarelyYes, if the agent puts it in
Who writes itThe clientThe agent, guided by your instructions

The sequence to instruct

Sume documents dry_run as an admission and cost preview that does not submit the job, and generation_admission_preview as a read tool for the same purpose. Prefer the preview before expensive bursts; Sume says ordinary single creates do not need admission theater, so do not add a form to every call.

Write the sequence into the agent instructions and test it once with a cheap tool.

  • Call tools_schema for the paid tool and read the fields.
  • Call the tool with dry_run: true, a fresh idempotency_key, and your max_spend_usd.
  • Call ask_user with the estimate and options: approve, adjust prompt, cancel.
  • On approval, repeat the call with dry_run omitted and the same max_spend_usd.
  • Call jobs_wait on the returned job id; on wait_slice_expired call it again.

A payload the agent can reuse

Here is the preview call body for an image create. The payload fields depend on the tool, so confirm them with tools_schema rather than copying this blindly.

{
  "idempotency_key": "zed-preview-2026-10-03-001",
  "dry_run": true,
  "max_spend_usd": 1,
  "payload": {
    "prompt": "A ceramic mug on a wooden table, soft morning light"
  }
}

Keep the preview key and the submit key distinct unless you are certain the platform treats them as one request; Sume documents idempotency_key as a stable key for transport and dedup, so reuse it only when retrying the same submit. A form can also be answered by a person who is not looking, so a ceiling in max_spend_usd remains the last line of defense. Do not rely on the form alone for a long-running agent thread; Zed's own setting that prevents idle sleep while agent threads run means a thread can keep working, and any billed job keeps running on Sume while you are away.

Wording the form well

A form is only as good as its text. Put the estimate first, in a single line a person can read at a glance, then the choices. Name the model or family if the router picked one, since the same prompt can cost differently across families, and say what happens on each choice: approve submits, adjust returns to the prompt, cancel ends the task without creating anything.

Avoid asking for approval of several paid calls in one form unless they are one unit of work. Approving ten things at once is how a person ends up agreeing to the eleventh. If the agent wants a batch, ask for a ceiling for the batch and use script_run with max_paid_calls, so the approved number and the enforced number are the same number.

Sources

Related posts

More in Agents

All Agents posts

Written by Sume