Agent Completions 403: service_account_agent_completions_unsupported
A Sume service-account key cannot create Agent Completions. It fails with 403 insufficient_scope and a reason code; use another key with the right scopes.

A service-account key cannot create Agent Completions. POST /v1/agent/completions fails with 403 insufficient_scope and details.reason set to service_account_agent_completions_unsupported, and no scope can be added to change that.
This comes from Sume's Agent Completions page. A different cause produces the same 403 insufficient_scope, an older key without the new scopes, so the details.reason field is how you tell them apart.
Which two things cause this 403?
Both return the same status and code.
| Cause | What the page says | Fix |
|---|---|---|
| Key created before Agent Completions shipped | Lacks agent_completions:read and agent_completions:write; scopes cannot be added to an existing key | Create a new key and rotate to it |
| Service-account key | Fails with service_account_agent_completions_unsupported | Use a non-service-account key |
Which scopes does a working key need?
agent_completions:write creates a completion and cancels a run. agent_completions:read reads and lists runs. A key that can create but not read cannot poll its own run, so give a backend both.
What do I do about it?
Create a key at the dashboard's API Keys page and use it for this call. The docs link Authentication for how keys and rotation work.
After the 403 clears, the next error you are likely to see is 400 invalid_request, because generation_spend_cap_usd is required and has no default. The page explains why: the interactive spend-approval prompt is not available to a backend caller, so the cap replaces it.
Does a Format run behave the same way?
The Agent Completions page covers only its own endpoint. For the Format and Scheduled run endpoints, read their own pages: the same code can have a different cause there.
Sources
Related posts
More in Agents
- Claude Code routines API trigger vs the Sume Scheduled run API
Claude Code routines' /fire endpoint and Sume's POST /v1/actions/{id}/runs both start a saved agent over HTTP. Compare payload, limits, receipts and webhooks.
- Which model runs a Sume scheduled agent, and how to choose it
A Sume schedule stores its own model beside its instructions and cap. Where to pick it, what Agent Completions accepts, and what the changelog says on defaults.
- hypit Understand order: one probe, then parallel batches
Sume's hypit Understand order: probe alone, then transcribe, boundaries and tiles in one batch, then notes. Which verbs wait on the transcript.
- How an agent picks a video model over hosted MCP
An agent reads video-router_models, picks an id, then calls generate_video with an idempotency_key and waits with jobs_wait. Omit the model for sume/auto.
Written by Sume