Gemini wrote your UrlFetchApp call for Sume: a review list

Gemini in the Apps Script editor is in beta. Before you run generated code against Sume, check it against this list of headers, keys, retries and status.

5 min readSume
All posts

What should you check when Gemini in the Apps Script editor writes a UrlFetchApp call to Sume? The Apps Script release notes list Gemini in the editor as a beta from August 3, requiring enrollment in the Gemini Beta program (read 2026-10-04). Generated code that calls a paid API is code you should read before the first run, because the first run may spend credits.

The list below is what to verify against Sume's documented behavior. Each item is a way a plausible-looking script can be wrong.

The review table

Read the generated code once against each row. None of this needs a test run, and most of it is visible in the first twenty lines.

Review list for generated Sume calls in Apps Script (read 2026-10-04)
CheckWhat Sume documentsCommon generated mistake
Auth headerOne of Authorization: Bearer or x-api-key; both returns 401Sets both headers
Where the key livesKeep keys out of shared places; rotate on exposureHard-coded string in the script
IdempotencyPaid writes should send Idempotency-KeyNo key, so a rerun buys again
Result handling202 means accepted, not finishedReads a media URL from the 202 body
ErrorsEnvelope {error:{code,message,request_id}}Assumes a plain text error
ExceptionsNon-2xx is a normal responseNo muteHttpExceptions, so a 4xx throws

Auth and the key

Sume accepts either header and rejects a request that sends both with 401 unauthorized. A generated snippet that copies a Bearer header from an example and adds x-api-key from another is a common way to hit this. Pick one.

The key belongs in Script Properties, read with PropertiesService, not in the source. Generated code often inlines a placeholder string; replace it before you save, and never paste the real key into the chat that produced the code. If you do, rotate it.

Idempotency and statuses

A paid request should carry an Idempotency-Key. Without one, running the function twice creates two jobs. With one derived from the row, a repeat returns the original job, and a changed payload under the same key returns 409.

The 202 response means the job was accepted. Generated code often treats it like a finished render and goes looking for an artifact URL. The real flow is to read the job id, then check GET /v1/jobs/:id/status, waiting next_poll_after_seconds, and call GET /v1/jobs/:id/result after completed. Artifacts are media.sume.com URLs.

A call that passes the list

This version of the free GET /v1/me check satisfies every row above that applies to a read: one header, key from properties, errors visible instead of thrown. Use it as the first function you let Gemini extend, and add paid calls yourself.

For batch behavior and quotas, see UrlFetchApp limits and Sume bulk runs. If you plan to receive webhooks in a web app, note that doPost cannot read headers, which affects signature checks. For a full example, read bulk AI videos from Sheets.

function checkSumeKey() {
  var key = PropertiesService.getScriptProperties().getProperty('SUME_API_KEY');
  if (!key) throw new Error('Set SUME_API_KEY in Script Properties');
  var res = UrlFetchApp.fetch('https://api.sume.com/v1/me', {
    headers: { 'x-api-key': key },
    muteHttpExceptions: true
  });
  var code = res.getResponseCode();
  Logger.log('GET /v1/me -> ' + code);
  if (code !== 200) Logger.log(res.getContentText());
  return code;
}

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume