Claude Code routine 403 host_not_allowed: allow Sume's hosts
A routine's curl to api.sume.com fails with 403 and x-deny-reason host_not_allowed on Trusted network. Which hosts to add, and why the connector is exempt.

A Claude Code routine on the Default environment uses Trusted network access, and a request from the session to a host outside the default allowlist fails with 403 and x-deny-reason: host_not_allowed. If your routine calls https://api.sume.com with curl, add api.sume.com to a Custom environment's Allowed domains, and add media.sume.com if it downloads finished files. A host named on an API credential is the other exception, since sessions can reach it whatever the network level says. The Sume connector is the third: its traffic goes through Anthropic's servers, so no allowlist change is needed for it.
Facts about the routine side come from the routines page and the cloud environments page read on 2026-10-03; Sume's hosts come from its Format API docs.
Why does the call fail?
Routines run in a cloud environment. The Default environment is Trusted, which the routines page says allows only the default allowlist of package registries, cloud provider APIs, container registries and common development domains. Anything else fails with that 403 and header.
The page also warns that a green status in the run list only means the session started and exited without an infrastructure error, so a blocked request surfaces in the transcript, not in the status indicator. Read the run when a Sume call returns nothing.
Which Sume hosts does a routine need?
It depends on how the routine talks to Sume. Hosted MCP through a connector needs nothing. A direct REST call needs the API host. Reading a result needs the media host, because Sume returns durable media.sume.com HTTPS URLs for generated files.
| Path | Host | Allowlist change |
|---|---|---|
| Sume connector (hosted MCP) | mcp.sume.com via Anthropic's servers | None |
| curl or SDK call to start a run | api.sume.com | Add to Allowed domains, or name it on an API credential |
| Download a generated clip or image | media.sume.com | Add to Allowed domains |
How do I change the network level?
- Open the routine, choose Edit, then the environment selector and its settings icon.
- Set Network access to Custom and list one domain per line, for example
api.sume.comandmedia.sume.com. Tick the box to keep the default list so package installs still work. - Save. The new policy applies from the next run.
- On an organization-shared environment the dialog is read-only; an Owner changes it from the Cloud environments page in admin settings.
- Choosing Full works but opens every domain; prefer the two named hosts.
How do I confirm the fix?
Have the routine run one read-only call first. A GET /v1/me with the key tells you whether the host is reachable before any paid run starts. The check below prints the status and the deny header, and it fails fast on a missing key.
import os, urllib.request, urllib.error
key = os.environ.get('SUME_API_KEY')
if not key:
raise SystemExit('set SUME_API_KEY first')
req = urllib.request.Request('https://api.sume.com/v1/me',
headers={'Authorization': 'Bearer ' + key})
try:
with urllib.request.urlopen(req, timeout=15) as r:
print(r.status)
except urllib.error.HTTPError as e:
print(e.code, e.headers.get('x-deny-reason'))
if e.headers.get('x-deny-reason') == 'host_not_allowed':
print('add api.sume.com to Allowed domains')Sources
Related posts
More in Developers
- Claude Code routines run hourly at most: use a Sume webhook
A routine's minimum schedule interval is one hour, so a polling loop wastes runs. Submit the Sume job once and let the terminal webhook trigger the next step.
- Claude Code routine skips approvals: cap Sume calls with script_run
A routine can use every tool without asking. Sume's script_run bounds a batch of calls with max_calls and max_paid_calls, so one run cannot fan out.
- Where to keep a Sume API key in a Claude Code routine
Environment variables are readable by anyone using the environment. On Pro and Max an API credential hides the key from Claude. What changes on Team plans.
- Claude Code mcp_server_errors: fail CI when Sume never loaded
In stream-json runs Claude Code reports a skipped MCP entry in mcp_server_errors. Check it with jq before a CI job spends on Sume, then verify with mcp_health.
Written by Sume