Bubble's agent can build API Connector calls: give it Sume's spec

Bubble's Agent can create API Connector calls on its own. Hand it Sume's OpenAPI JSON, the single-header rule and a free GET /v1/me to initialize.

5 min readSume
All posts

Can Bubble's Agent set up the Sume API Connector for you? According to Bubble's September founder AMA, the Agent runs on Claude Sonnet 5 and can create API Connector calls on its own (read 2026-10-04). That saves the clicking, but it moves the risk: an agent filling in a connector will invent whatever you do not specify. For Sume that means three things to state up front: where the OpenAPI spec is, that exactly one auth header is allowed, and which free call to use to initialize.

With those three in the prompt, the connector comes out right the first time, and the Agent has no reason to guess at endpoint shapes.

Hand it the spec, not a description

Sume publishes its OpenAPI document at https://api.sume.com/reference/json. Tell the Agent to read request and response shapes from there rather than from memory. This matters most for jobs: a paid request returns 202 with identifiers, and the Agent should model the response fields from the spec instead of assuming a finished media URL.

Also point it at the human reference, the API reference, for the rules the spec does not spell out, such as the idempotency behavior.

The single-header rule

Sume accepts either Authorization: Bearer <key> or x-api-key: <key>. Sending both returns 401 unauthorized with the message "Send only one API key credential." An agent that sees a Bubble connector with a shared header and adds its own is exactly how this happens. Tell it plainly: one shared header, x-api-key, marked private, with the key stored as a private value.

Mark the key private so it is not sent from the browser. Sume's guidance is to keep keys out of frontend code, and a Bubble API Connector call run on the server side with a private header satisfies that.

Instructions that keep an agent-built connector correct (read 2026-10-04)
Instruction to the AgentWhat it prevents
Use x-api-key as the only auth header401 from a doubled credential
Mark the key privateThe key reaching the browser
Initialize with GET /v1/meSpending credits during setup
Read shapes from reference/jsonInvented fields in responses
Send Idempotency-Key on paid callsDuplicate paid jobs on retry

Initialize with a free call

Bubble's connector asks you to initialize a call so it can learn the response shape. Do that with GET /v1/me, which Sume documents as a free read, so no setup step costs credits. The related reads GET /v1/balance, GET /v1/usage and GET /v1/catalog are also free if you want more calls in the connector.

Before you hand the connector to the Agent, confirm the key from a terminal. If this prints 200, the key and header are right and any later failure is in the connector, not the key.

curl -sS -o /dev/null -w '%{http_code}\n' https://api.sume.com/v1/me -H "x-api-key: $SUME_API_KEY"

Paid calls and jobs

Do not let the Agent initialize a paid call. Initializing runs the request, and a paid request starts a real job. Add paid calls yourself, give each an Idempotency-Key, and treat the 202 as accepted, not finished: store the job id, then poll GET /v1/jobs/:id/status, honoring next_poll_after_seconds.

Bubble also said an MCP beta is coming in two to three weeks, which is a separate path and not something to build on yet. For the manual walkthrough of the same connector, read the Bubble API Connector guide, and for another tool that consumes the same spec, see Dify custom tools from the OpenAPI document.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume