OpenAI Agents SDK MCP tool_input_guardrails for Sume spend
tool_input_guardrails on an Agents SDK MCP server can reject a call before it runs. For Sume paid tools, check idempotency_key and max_spend_usd.

tool_input_guardrails is a list you pass to an Agents SDK MCP server object. Each guardrail reads the tool arguments and either allows the call or rejects it with a message. For Sume's paid tools you can use one to refuse any call that lacks idempotency_key or max_spend_usd, before the request leaves your process.
The SDK behavior is from OpenAI's MCP page. The gate fields are from Sume's MCP tools and gates, both read 2026-09-30.
Which MCP objects accept tool_input_guardrails?
The page says the setting applies only to tools exposed by local MCP server objects such as MCPServerStdio, MCPServerSse and MCPServerStreamableHttp. It does not add client-side guardrails to HostedMCPTool, which the Responses API executes as a hosted tool. So a guardrail on a hosted tool will not run.
What does Sume require on a paid call?
Three gate fields matter. Only the first is required.
| Field | Required? | Meaning in the docs |
|---|---|---|
idempotency_key | Required on write and paid tools | Stable key for transport/dedup, not human approval |
dry_run=true | Optional | Admission/cost preview only; do not submit the job |
max_spend_usd | Optional | Enforced only when provided |
What does a guardrail for these look like?
Same shape as OpenAI's example, which rejects arguments containing a secret. Here it requires a spend cap. It only checks arguments, and as written it runs for every tool on that server, so read tools without these fields would be rejected too. Attach it to a server used only for paid calls, or branch on the tool name your SDK version exposes.
import json
from agents import ToolGuardrailFunctionOutput
from agents.decorators import tool_input_guardrail
@tool_input_guardrail
def require_spend_cap(data):
args = json.loads(data.context.tool_arguments or "{}")
if "max_spend_usd" not in args or "idempotency_key" not in args:
return ToolGuardrailFunctionOutput.reject_content(
"Add idempotency_key and max_spend_usd before a paid Sume call."
)
return ToolGuardrailFunctionOutput.allow()Is a guardrail the same as approval?
No. The Sume docs say idempotency_key is for transport and dedup, not human approval. A guardrail checks arguments; approval is a separate step. For the approval side see Vercel AI SDK tool approval for paid video.
Connect the server at https://mcp.sume.com/mcp, as in the quickstart.
Sources
Related posts
More in Developers
- OpenAI Agents SDK MCPServerManager with a Sume server
Run Sume next to another MCP server in the OpenAI Agents Python SDK: connect Sume over streamable HTTP, check it with mcp_health, and read tools_list.
- OpenAI Batch API limits vs Sume bulk runs: 50,000 vs 100
OpenAI Batch allows 50,000 requests per file with a 24h window. A Sume Format bulk run takes 1-100 items at concurrency 1-16, so chunk your file accordingly.
- OpenAI-compatible /v1/audio/speech: what Sume's TTS route is
Sume has no `/v1/audio/speech` clone. Its TTS is `POST /v1/tts-1.0/generate` or the Router, a job-based request authenticated with a Sume key.
- OpenAI whisper-1 shutdown Feb 2027: a Sume STT alternative
OpenAI removes whisper-1 on Feb 26, 2027. Sume's STT request names no provider model, takes a public audio URL, and caps reserved duration at 10 minutes.
Written by Sume