Anthropic x-api-key is now a fallback: Sume accepts one header
Anthropic's docs list Authorization: Bearer first and call x-api-key a legacy fallback. Sume accepts either, but rejects a request that sends both with a 401.

Anthropic's API overview now lists Authorization: Bearer first and describes x-api-key as a "Legacy fallback for Authorization, still supported". Sume accepts both forms too, but a request carrying both gets 401 unauthorized with Send only one API key credential. Pick one header per integration.
Anthropic's wording is from its API overview; Sume's from Authentication, both read 2026-09-30.
What changed on the Anthropic side?
The overview's header table shows Authorization as Bearer <token> and marks it as needed "unless x-api-key is set". x-api-key is described as your API key from Console, kept as a legacy fallback. Clients that used to send only x-api-key still work there.
Which header does Sume want?
| Request | Anthropic docs | Sume docs |
|---|---|---|
Authorization: Bearer only | Listed first | Accepted |
x-api-key only | Legacy fallback, still supported | Accepted; the Sume CLI defaults to it |
| Both headers | Not covered in the snapshot | 401 unauthorized; neither header wins |
How do I end up sending both?
The Sume docs name the cause: gateways and fetch wrappers that add their own Authorization header on top of a client that already sends x-api-key. They advise stripping one rather than relying on a precedence rule. The 401 itself is covered in send only one.
What should I standardize on?
For a new Sume integration, use Authorization: Bearer $SUME_API_KEY to match the order Anthropic now shows, and remove x-api-key from any shared client or proxy that injects headers. Sume documents both as accepted, so this is a consistency choice, not a requirement.
Sources
Related posts
More in Developers
- AI Act Article 50 in force: what to log per generated file
Article 50 applies from 2 August 2026. Keep a per-file record of job id, request id and artifact URL from Sume, and know what the docs leave unsaid on marking.
- AI Act Article 50 and standard editing: which Sume tools use no model
The Commission's FAQ exempts assistive standard editing from AI marking. Sume's trim, filter, audio detach and timeline docs call themselves ffmpeg-only.
- Speaker diarization API: confidence scores, and what Sume STT returns
AssemblyAI added speaker_confidence (0 to 1) per word and utterance. Sume STT returns word start and end times only, with no speaker or confidence data.
- Why Sume Agent Completions rejects assistant messages
An assistant turn in messages[] returns 400 invalid_request on Sume Agent Completions. Only system and user turns work; each call runs in a fresh thread.
Written by Sume