Mastra respondToToolApproval needs toolCallId: Sume paid calls
Mastra now rejects approval responses without toolCallId. When you approve a Sume paid tool call, key it to that id and keep its idempotency_key stable.

Mastra's release notes list a breaking change: session.respondToToolApproval(...) now requires toolCallId, and id-less approval responses are rejected. For a Sume paid tool call, send the approval with the id of the exact call you showed the user, and keep that call's idempotency_key unchanged if you retry.
Vendor facts are from the Mastra releases page; Sume facts from MCP tools and gates and Jobs and results, read 2026-10-01.
What changed in Mastra?
Besides the required toolCallId, the same note says related approval APIs now key gates per thread and run, and grant scoping was updated. Check your own approval code against that note; this post does not cover the rest of the release.
Is a Sume idempotency_key the same as an approval?
No. The docs describe idempotency_key as a stable key for transport and dedup, not human approval. Two ids do two jobs here.
| Id or gate | Purpose |
|---|---|
toolCallId (Mastra) | Ties an approval to one pending tool call |
idempotency_key (Sume) | Required on write and paid tools; transport and dedup |
dry_run=true | Admission and cost preview only; no job submitted |
max_spend_usd | Enforced only when provided |
How should I wire the approval?
Ask for approval before the paid call runs, using the call id Mastra gives you. Show the user a dry_run result first when the spend is large; the docs prefer generation_admission_preview and/or dry_run before expensive bursts. Write tools are marked readOnlyHint: false in the server's tool results, which is a useful flag to require approval on.
What if the approved call is retried?
Reuse the same key only for the same operation and payload. A changed payload needs a new key. If an approval times out or the connection drops, read the job state instead of submitting again; see Mastra background tasks and Sume job leases.
Sources
Related posts
More in Integrations
- MCP Enterprise-Managed Authorization is stable: Sume uses OAuth or key
The MCP roadmap calls Enterprise-Managed Authorization stable. Sume's hosted MCP documents two sign-in modes: OAuth with scopes, or an API key.
- Notion 600 requests/min per connection: write back 100 Sume results
Notion allows 600 requests per minute per connection on Business and Enterprise, 180 elsewhere. Here is how to write 100 finished Sume results back within that.
- OpenAI Agents Python conditional approval and Sume dry_run
Openai-agents-python v0.22.3 aligns conditional approvals with validated tool arguments. For Sume tools, base the check on tools_schema and dry_run.
- Oversized MCP result: Cline cache URI vs Sume 256 KiB limit
Cline caches oversized MCP output behind a cline://cache URI. Sume instead refuses at 256 KiB with mcp_output_too_large. Re-read narrower; never resubmit.
Written by Sume