Cloudflare Access strict mode: token headers on every Sume poll
Strict service token auth issues no CF_Authorization cookie, so a Sume job poller behind Access must send its token every time. Triage 401, 403 and Sume errors.

If a service of yours polls Sume jobs through an endpoint protected by Cloudflare Access, strict service token authentication means it must send its service token headers on every request: Access no longer returns a CF_Authorization cookie after a service-token request succeeds, so a cookie jar will not carry the session for you. A 401 or 403 from Access is not a Sume error, and the way to tell them apart is that Sume's errors are a JSON envelope with error.code and a request_id.
Cloudflare's behavior is from its 2026-10-02 changelog entry. Sume's side is from Authentication, Jobs and results and Errors and rate limits, read 2026-10-03. This is a design note, not a run against a live Access application.
Where does the Sume key go?
Sume accepts either Authorization: Bearer <key> or x-api-key: <key>, and exactly one. A request carrying both is rejected with 401 unauthorized and the message Send only one API key credential. That matters here because a proxy or gateway that adds its own Authorization header on top of a client that already sends x-api-key will break every call.
Keep the two credentials separate by purpose: the Access service token authenticates your poller to your own protected service, and the Sume key authenticates that service to Sume. The Sume key stays on the server side and never goes to a browser.
How do I tell an Access failure from a Sume failure?
Poll with GET /v1/jobs/{id}/status, honor next_poll_after_seconds when present and back off otherwise, and stop on terminal. When a poll fails, read the body before deciding whether to retry. A failed poll never justifies resubmitting the paid create: Sume's docs say not to resubmit the original paid request because a local process timed out.
| What you see | Who answered | What to do |
|---|---|---|
401 or 403, not a Sume JSON envelope | Access | Check the service token headers and Service Auth policy; the job is untouched |
401 unauthorized with Send only one API key credential. | Sume | Strip one of Authorization and x-api-key |
401 unauthorized, other message | Sume | The key is missing, malformed or revoked |
404 not_found | Sume | The job is not in this workspace, or this key's member did not create it |
429 rate_limited | Sume | Back off using retry-after when present |
302 to a login page | Access, strict mode off | Enable strict mode or send the token headers |
Sources
Related posts
More in Developers
- Cloudflare Agents addMcpServer for Sume: streamable-http and headers
Connect a Cloudflare Agent to Sume's hosted MCP server with addMcpServer, an explicit streamable-http transport and a bearer header, and keep jobs resumable.
- Cloudflare portal Code Mode policy vs Sume script_run
Both shrink tool-call overhead, in different places. What Cloudflare's portal Code Mode policy controls and when Sume script_run is the other half.
- Cloudflare MCP portal logs: telling Sume read and paid calls apart
Portal logs record tool activity and Logpush exports it. Which Sume tool names mean spend, so a SIEM rule can flag them without reading arguments.
- How to compare AI video models fairly: one prompt, three models, 480p
Submit one prompt to Seedance 2.0 Mini, Wan 3.0 and MiniMax H3 at 480p and 5 seconds on Sume, then judge the clips blind. A runnable Python test harness.
Written by Sume