claude -p --permission-prompt-tool with Sume paid jobs
Headless claude -p can route permission prompts to an MCP tool. For Sume paid jobs, keep idempotency_key stable and wait with jobs_wait in 55s slices.

With claude -p --permission-prompt-tool <tool>, permission prompts go to an MCP tool you name instead of a person. Since v2.1.285 that includes a background subagent's request. Whatever that tool answers, a paid Sume call still needs its own idempotency_key, and a local timeout is never a reason to submit the create again: re-read the job with jobs_wait.
Claude Code facts are from its CLI reference and release notes; Sume facts from MCP tools and gates and Jobs and results, read 2026-09-30.
What does the flag do?
The CLI reference says it specifies an MCP tool to handle permission prompts in non-interactive mode. Claude Code waits for that tool's MCP server to connect before the first turn, up to the MCP_TIMEOUT startup timeout, 30 seconds by default. It cannot approve an MCP tool marked as requiring user interaction. The v2.1.285 notes say a background subagent's permission request now goes to the prompt tool instead of being auto-denied.
What still protects a paid Sume call?
| Layer | Control | Source |
|---|---|---|
| Claude Code | --permission-prompt-tool answers the prompt | CLI reference |
| Sume's MCP | idempotency_key required on write and paid tools | MCP tools and gates |
| Sume CLI | --confirm-paid for generation that can reserve or spend credits | Agent skills (CLI) |
| Waiting | jobs_wait holds at most 55s per call | Jobs and results |
How do I wait on a job in a -p run?
Call jobs_wait with the job id. Each call holds at most 55 seconds (default 50); on wait_slice_expired, call it again with the same ids rather than resubmitting. This keeps one turn from depending on a single long request; see jobs_wait for long video jobs.
What should the prompt tool decide?
Keep it simple: allow read tools, and for paid calls allow only when the input carries max_spend_usd and an idempotency_key you generated before the run. Connect Sume with claude mcp add --transport http sume https://mcp.sume.com/mcp; the unattended setup is in headless MCP config for Sume video, and connect-time waits in the startup timeout post.
Sources
Related posts
More in Developers
- claude plugin validate and an insecure URL in .mcp.json
Claude Code 2.1.283 added MCP checks to claude plugin validate, including insecure URLs. Sume's hosted endpoint is https, so a plain entry has nothing to flag.
- D1 free-tier limit now fails queries: dedupe Sume webhooks safely
Cloudflare D1 queries on Workers Free now fail past the daily row limits. Dedupe Sume webhooks on request_id, return a 5xx, and use redeliver after the reset.
- Cloudflare Worker 64 MiB limit and the Sume SDK bundle
Cloudflare now checks only a 64 MiB uncompressed Worker bundle. @sume-com/sdk has no runtime dependencies and runs on Workers; measure with a dry run.
- Start a Cloudflare Workflow from a Sume webhook with ctx.exports
Verify the Sume webhook signature in a Worker, then start a Workflow with ctx.exports and no workflows binding. Includes a short Worker handler.
Written by Sume