Audit who can run your Format: list grants, pending versus accepted
GET .../grants lists pending and accepted workspace grants on a Format, newest first, without revoked ones. Script a weekly audit and revoke what is stale.

To see which workspaces can run your Format, call GET /v1/formats/{handle}/{slug}/grants with formats:read and a key created in the Format's own team workspace. It lists the live grants, pending and accepted together, newest first, and leaves out revoked ones, so what you read is exactly who could call the address right now or could once they accept.
Reading the list
Each entry in data is a format.grant object with an fgr_ id, grantee_workspace_id, grantee_workspace_handle, the role (run or write) and a status. pending means invited but not accepted, which confers nothing. accepted means the grantee can use the role.
A pending entry that has sat for weeks is a cleanup candidate: either the partner never received the invite, or the deal fell through. Withdrawing it is a plain revoke.
import os, requests
base = "https://api.sume.com/v1/formats/acme/product-promo/grants"
h = {"Authorization": "Bearer " + os.environ["SUME_API_KEY"]}
r = requests.get(base, headers=h, timeout=30)
r.raise_for_status()
for g in r.json().get("data", []):
print(g["id"], g["status"], g["role"], g["grantee_workspace_handle"])What to check each time
| Check | Why it matters | Action |
|---|---|---|
| Pending for a long time | No access is conferred, but the id still blocks a new invite | Revoke, then re-invite if needed |
| Role write | The grantee can edit the package at your address | Lower to run with PATCH if the edit work is done |
| Workspace you do not recognize | Access should come only from your invite | Revoke |
| Accepted run grant on a closed project | It still allows invocation | Revoke; in-flight runs finish |
Keep it cheap
The list is a read, so it spends the read budget and no credits. Run it from a weekly job and compare with your own record of who you invited. If the list shows a workspace that your records do not, that is a prompt to find out who invited it from the dashboard's Access tab, which can create live grants without the API.
A routine that scales
If you share a Format with many client workspaces, put the audit on a calendar. Each Monday, list the grants, diff the result against yesterday's copy, and post any new or changed row to the channel your team reads. A new write grant or a workspace nobody remembers inviting deserves a human look the same day.
Pair the audit with an offboarding rule: when a contract ends, the revoke is the first task, not the last. A revoke is complete by construction because nothing was copied to the grantee, so there is no data to chase down afterward. The runs already started finish on the grantee's own bill.
Record the fgr_ id next to each partner in your own system. It makes every later revoke or role change a one-line job.
Limits
The list does not show how much a grantee has spent or how many runs they made; those belong to the grantee's workspace and bill, and you cannot read their runs. If you need usage numbers for a partner, ask them for their own usage export.
Revoked grants disappear from the list, so keep your own log of revocations, including the revoked_at value that the revoke call returns.
Sources
Related posts
More in Formats
- Back-in-stock video for one SKU: send the facts as input, not prose
One restock clip is one Format run: put SKU, stock count and ship date in an input object, add a short instruction, and key the run by SKU and date.
- Black Friday ad copy and video in one call: an output_schema example
Bind an output_schema with headline, caption and a SumeMediaFile video so one Format run returns typed copy and the clip together, with primary_output_key set.
- Bulk queue concurrency 16 but fewer runs start: workspace concurrency
Concurrency 16 is a ceiling on the queue, not a promise. Workspace generation concurrency still applies to every child, so some start late or fail to start.
- A queue of 100 Shorts: unique input and a cap per item
Sume bulk runs queue up to 100 Format runs. Give each item its own input and spend cap so no two Shorts read alike. Limits and a request shape from the docs.
Written by Sume