Cloudflare Sandbox SDK 1.0: run the Sume SDK inside one

The @sume-com/sdk has no runtime dependencies and needs only fetch and WebCrypto, so it can run in a sandbox. Pass the key as an env var, server-side only.

4 min readSume
All posts

@sume-com/sdk has no runtime dependencies and needs only fetch and WebCrypto, so it can run inside a code sandbox on Node 18+, Bun, Deno or Workers. Install it in the sandbox, pass SUME_API_KEY in as an environment variable, and keep the key out of anything the sandbox can print.

What Cloudflare announced

The Cloudflare changelog for Sep 30, 2026 lists Sandbox SDK 1.0 and says "Your own Durable Object class now controls each sandbox container directly". This post uses only that line. It does not describe how to start processes or set environment variables in a sandbox, so use Cloudflare's own documentation for that.

What the Sume SDK needs

The Sume docs publish @sume-com/sdk@0.2.0, MIT licensed, with no runtime dependencies. It needs fetch and WebCrypto: Node 18+, Bun, Deno or Cloudflare Workers.

The client sends x-api-key only. Do not add an Authorization header: a request carrying both fails with 401 unauthorized. If you wrap fetch through the fetch option, make sure the wrapper adds none. Always pass the client you created to each call; the module default has no key.

SDK facts (read 2026-10-03)
ItemValue
Package@sume-com/sdk 0.2.0
Runtime dependenciesNone
RuntimesNode 18+, Bun, Deno, Workers
Auth headerx-api-key only
Default job wait timeout20 minutes

A script to run inside the sandbox

This is the docs' waitForJob example, with the key read from the environment. Submit with mode: "async", then wait client-side.

import { createSumeClient, generateVideoV1, waitForJob } from "@sume-com/sdk";

const client = createSumeClient({ apiKey: process.env.SUME_API_KEY! });

const { data: submitted, error } = await generateVideoV1({
  client,
  headers: { "idempotency-key": crypto.randomUUID() },
  body: { prompt: "Slow push-in on a ceramic mug", mode: "async" },
});
if (error) throw new Error(JSON.stringify(error));

const job = await waitForJob(submitted!.data.request_id, { client });
console.log(job.status, job.result.artifacts);

Server-side only, and short-lived

A Sume API key spends your credits and there is no browser-safe variant, so the sandbox must be your own server-side environment. Never print the key or write it to a file the sandbox returns.

A sandbox may stop before a long job finishes. A timeout does not cancel the job; it keeps running and billing. Print the job id before waiting, so a later process can read it with getApiJob or cancel it with cancelApiJob. For long renders, prefer a webhook and verify it with verifyWebhook.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume