Cloudflare Access strict mode: token headers on every Sume poll

Strict service token auth issues no CF_Authorization cookie, so a Sume job poller behind Access must send its token every time. Triage 401, 403 and Sume errors.

5 min readSume
All posts

If a service of yours polls Sume jobs through an endpoint protected by Cloudflare Access, strict service token authentication means it must send its service token headers on every request: Access no longer returns a CF_Authorization cookie after a service-token request succeeds, so a cookie jar will not carry the session for you. A 401 or 403 from Access is not a Sume error, and the way to tell them apart is that Sume's errors are a JSON envelope with error.code and a request_id.

Cloudflare's behavior is from its 2026-10-02 changelog entry. Sume's side is from Authentication, Jobs and results and Errors and rate limits, read 2026-10-03. This is a design note, not a run against a live Access application.

Where does the Sume key go?

Sume accepts either Authorization: Bearer <key> or x-api-key: <key>, and exactly one. A request carrying both is rejected with 401 unauthorized and the message Send only one API key credential. That matters here because a proxy or gateway that adds its own Authorization header on top of a client that already sends x-api-key will break every call.

Keep the two credentials separate by purpose: the Access service token authenticates your poller to your own protected service, and the Sume key authenticates that service to Sume. The Sume key stays on the server side and never goes to a browser.

How do I tell an Access failure from a Sume failure?

Poll with GET /v1/jobs/{id}/status, honor next_poll_after_seconds when present and back off otherwise, and stop on terminal. When a poll fails, read the body before deciding whether to retry. A failed poll never justifies resubmitting the paid create: Sume's docs say not to resubmit the original paid request because a local process timed out.

Triage table built from Cloudflare's changelog and Sume's errors page, read 2026-10-03.
What you seeWho answeredWhat to do
401 or 403, not a Sume JSON envelopeAccessCheck the service token headers and Service Auth policy; the job is untouched
401 unauthorized with Send only one API key credential.SumeStrip one of Authorization and x-api-key
401 unauthorized, other messageSumeThe key is missing, malformed or revoked
404 not_foundSumeThe job is not in this workspace, or this key's member did not create it
429 rate_limitedSumeBack off using retry-after when present
302 to a login pageAccess, strict mode offEnable strict mode or send the token headers

Sources

Related posts

More in Developers

All Developers posts

Written by Sume