Cloudflare Sandbox SDK 1.0: run the Sume SDK inside one
The @sume-com/sdk has no runtime dependencies and needs only fetch and WebCrypto, so it can run in a sandbox. Pass the key as an env var, server-side only.

@sume-com/sdk has no runtime dependencies and needs only fetch and WebCrypto, so it can run inside a code sandbox on Node 18+, Bun, Deno or Workers. Install it in the sandbox, pass SUME_API_KEY in as an environment variable, and keep the key out of anything the sandbox can print.
What Cloudflare announced
The Cloudflare changelog for Sep 30, 2026 lists Sandbox SDK 1.0 and says "Your own Durable Object class now controls each sandbox container directly". This post uses only that line. It does not describe how to start processes or set environment variables in a sandbox, so use Cloudflare's own documentation for that.
What the Sume SDK needs
The Sume docs publish @sume-com/sdk@0.2.0, MIT licensed, with no runtime dependencies. It needs fetch and WebCrypto: Node 18+, Bun, Deno or Cloudflare Workers.
The client sends x-api-key only. Do not add an Authorization header: a request carrying both fails with 401 unauthorized. If you wrap fetch through the fetch option, make sure the wrapper adds none. Always pass the client you created to each call; the module default has no key.
| Item | Value |
|---|---|
| Package | @sume-com/sdk 0.2.0 |
| Runtime dependencies | None |
| Runtimes | Node 18+, Bun, Deno, Workers |
| Auth header | x-api-key only |
| Default job wait timeout | 20 minutes |
A script to run inside the sandbox
This is the docs' waitForJob example, with the key read from the environment. Submit with mode: "async", then wait client-side.
import { createSumeClient, generateVideoV1, waitForJob } from "@sume-com/sdk";
const client = createSumeClient({ apiKey: process.env.SUME_API_KEY! });
const { data: submitted, error } = await generateVideoV1({
client,
headers: { "idempotency-key": crypto.randomUUID() },
body: { prompt: "Slow push-in on a ceramic mug", mode: "async" },
});
if (error) throw new Error(JSON.stringify(error));
const job = await waitForJob(submitted!.data.request_id, { client });
console.log(job.status, job.result.artifacts);Server-side only, and short-lived
A Sume API key spends your credits and there is no browser-safe variant, so the sandbox must be your own server-side environment. Never print the key or write it to a file the sandbox returns.
A sandbox may stop before a long job finishes. A timeout does not cancel the job; it keeps running and billing. Print the job id before waiting, so a later process can read it with getApiJob or cancel it with cancelApiJob. For long renders, prefer a webhook and verify it with verifyWebhook.
Sources
Related posts
More in Developers
- Cloudflare Worker for Sume webhooks: log fields a dashboard needs
Cloudflare added Workers Observability to Custom Dashboards on Oct 1. A Sume webhook Worker should log event, job_id, outcome and the secret fingerprint.
- Codex 0.160 agent history 'Show more': recover Sume jobs by job list
Codex CLI 0.160.0 adds Show more pagination to agent command center history. If a thread scrolls away, Sume's GET /v1/jobs list still holds every job.
- Computer-use agent or API call: use Sume jobs, not clicks
OpenAI added computer use to its Agents API on Sep 29, 2026. For media generation, an agent should call Sume's API or MCP tools rather than click a dashboard.
- Join two generated tracks without a gap: timeline audio concat
One Lyria generation too short? Join up to 20 Sume-hosted audio files into one gapless wav with timeline audio concat and read segment offsets.
Written by Sume