Computer use origin approval is not a spend approval
OpenAI's computer use approves each new website origin, not spend. When such an agent calls Sume, the spend check is dry_run, max_spend_usd and the wallet.

No. The approval OpenAI's hosted browser asks for is about website origins, not money. If a computer-use agent also calls Sume, the spend control is on the Sume side: dry_run, an optional max_spend_usd, and the workspace wallet.
The computer use guide, read 2026-09-30, says the browser requires the user's approval before accessing each new website origin, including public websites, and that enabling network access does not approve these requests. A pending computer_use_approval_request with request type browser_origin_access appears in required_actions, and you collect approve, deny or cancel.
What does a Sume tool call check instead?
Sume's MCP tools and gates lists the gates. None of them is a human approval step.
| Gate | What the docs say |
|---|---|
idempotency_key | Required on write and paid tools; stable key for transport/dedup, not human approval |
dry_run=true | Optional; admission/cost preview only, does not submit the job |
max_spend_usd | Optional; enforced only when provided |
| Scope | Write and paid tools hidden until mcp:write or an API key; no mcp:paid scope |
Where should the spend approval live?
In your own agent loop. Before the first paid call, have the agent run dry_run=true or generation_admission_preview, show the preview to the user, and submit only after approval. Pass max_spend_usd on the submit so the cap is actually enforced, since it applies only when provided. A pattern for a human gate around paid tools is in OpenAI Agents SDK human-in-the-loop paid tools.
Does approving an origin grant access to Sume?
Nothing in either source says so. Sume access comes from the session: an API key or OAuth mcp:write makes the write and paid tools visible, and spend is wallet and admission. Treat the two approvals as separate, and give the agent a key you can revoke.
Sources
Related posts
More in Developers
- Content Credentials after download: check the file you deliver
C2PA 2.2 defines Content Credentials and a separate Soft Binding API. Sume's docs do not say a downloaded output keeps one, so check the delivered file.
- Can I continue a Sume Agent Completion with thread_id?
Not yet. Every Agent Completion runs in a fresh thread, so a follow-up call cannot reuse thread_id. Pass earlier results back in the next request instead.
- Crawl job finished event: Sume has none, poll crawl_get
Cloudflare publishes crawl.finished to Queues. Sume's crawl has no such event: wait on the job id, then read it with crawl_get. Steps and idempotency.
- curl 8.22 RFC 9421 signatures vs the Sume webhook signature
curl 8.22.0 adds experimental RFC 9421 HTTP Message Signatures. A Sume webhook is not one: it is an HMAC over timestamp.body in a sume-v1 header.
Written by Sume