Airtable attachment URLs expire in hours: feeding Sume an image
Airtable attachment download URLs expire after at least 2 hours, and Sume accepts only fetchable public HTTPS media URLs. Copy the image to a stable URL first.

Do not pass an Airtable attachment's download URL straight to Sume as an image input. Airtable says those links expire, and that it keeps them active for at least 2 hours after you receive them. Sume's media inputs page says inputs must be fetchable public HTTPS URLs, and that signed or private URLs are rejected before generation. Copy the file to a stable public HTTPS location first, or keep the picture's public URL in a URL field.
The Airtable facts are from Airtable's attachment URL behavior page (read 2026-10-02); the Sume rules from Media inputs. Neither page promises how Sume treats a still-valid Airtable download URL, so this post does not rely on it working.
What kinds of Airtable attachment URL exist?
Airtable's page names two types. A viewer URL needs base or interface access, and stops working if the attachment or its record is deleted. An expiring download URL needs no Airtable access, lives on the airtableusercontent.com domain, and expires for security reasons. The page adds that links stored in single line text, long text or URL fields are unaffected.
| URL type | Access needed | Lifetime | As a Sume image input |
|---|---|---|---|
| Attachment viewer URL | Airtable sign-in and base access | Until the attachment or record is deleted | No: not a public URL |
| Expiring download URL | None | Short; at least 2 hours after you get it | Not a safe input: it expires and may count as a signed URL |
| Link in a URL or text field | None | Whatever the host decides | Yes, if public HTTPS and fetchable |
Why does expiry matter for a queued job?
Sume accepts valid paid jobs as queued while workers are busy, and a video can run for minutes after it starts. Sume's docs say it fetches and mirrors input media before generation; if it cannot, you see image_not_fetchable or input_media_unreachable, whose next step is to check that the input is a public HTTPS image URL and retry. An expiring link makes that failure depend on timing. A stable URL removes the variable.
Airtable also says automations can read the expiring download URL for use cases meant to expire, and that its API consumers should download attachments before the links expire. That is the step to add: download, then host.
How do I set it up in an automation?
Trigger on a record, read the attachment field, download the file during the same run (the URL is fresh then), and upload it to storage you control that serves a public HTTPS URL without hotlink blocking; the hotlink post covers how a protected host fails. Write that URL to a URL field, send it as the Sume image field (for example input.image_url for an Avatar 1.0 photo), and store the job id in the record. Add an Idempotency-Key built from the record id so a rerun returns the same job.
What about the result going back into Airtable?
Sume's completed jobs return artifact URLs under media.sume.com, which Sume's docs call the public contract. Write the URL into a URL field rather than relying on any provider link. Per Airtable's page, a link in a URL field is not subject to the attachment expiry. See one video per record for the full flow.
Sources
Related posts
More in Integrations
- Airtable upsert with fieldsToMergeOn: one row per Sume job id
Airtable's performUpsert merges on 1-3 fields. Merge on a Sume job_id field so webhook retries update one row instead of creating duplicates.
- Airtable webhook expired after 7 days: refresh it, then batch Sume
Airtable webhooks made with a token expire after 7 days and stop after 13 failed pings. Refresh on a schedule, then send changed rows to one Sume bulk run.
- Amp MCP server: amp mcp remote add with a bearer token file for Sume
Add Sume's hosted MCP to Amp with amp mcp remote add --auth bearer --bearer-token-file, so the Sume API key never appears in a command line.
- Apps Script doPost and the Sume webhook signature: what you can verify
An Apps Script web app doPost documents the body but no headers, and Sume signs in headers. Treat the callback as a hint and re-read the job with your key.
Written by Sume