curl -K config file: keep your Sume API key out of ps output
A key passed with -H shows in ps args and shell history. curl -K reads headers from a chmod 600 file instead. Tested on curl 8.7.1 against a stub.

Any process on the machine can list your running commands, and curl -H "x-api-key: sk_..." puts the key in that list for as long as the request runs. On a slow download or a hung connection that can be minutes. It also lands in shell history. curl -K file (long form --config) reads options from a file, so the command line carries no secret.
Checked on curl 8.7.1 against a local listener that never answered: ps -o args= printed curl -s --max-time 3 -H x-api-key: SECRETKEY123 http://127.0.0.1:8895/ for the -H form and curl -s --max-time 3 -K sume.curlrc http://127.0.0.1:8896/ for the config form.
Create the file with tight permissions
Sume's dashboard shows the full key once, at creation. Paste it into the file straight from there. umask 077 makes the file readable only by you (-rw-------).
umask 077
cat > sume.curlrc <<EOF
header = "x-api-key: $SUME_API_KEY"
header = "content-type: application/json"
EOFUse it
The config adds the headers; the rest of the command stays readable and safe to paste into a ticket. The submit below returned 202 from a stub.
curl -s -K sume.curlrc -H 'Idempotency-Key: kite-k-1' \
-d '{"model":"wan-3.0","prompt":"a red kite","duration":5,"resolution":"480p"}' \
https://api.sume.com/v1/videosLimits of the trick
The key is now in a file, so treat the file like the key: never commit it, delete it on shared machines, and rotate if it leaks. Environment variables are not safer from ps on every platform. Prefer your CI's secret store and write the file at job start. Use one header only; sending both x-api-key and Authorization: Bearer returns 401.
Sources
Related posts
More in Developers
- Cursor project .cursor/mcp.json or global ~/.cursor/mcp.json for Sume?
Put a URL-only Sume entry in .cursor/mcp.json to share it with a repo, and keep any API key in an env variable in the global file, not in git.
- Cut a 10-minute recording into 3-minute Reels with video trim
A 600 s recording becomes four trims: 180, 180, 180 and 60 s, $0.08 in total. Python loop with a safe Idempotency-Key per segment; run it with an imported file.
- Cut a YouTube Short on the beat: BPM to cut times in Python
Turn a music bed's BPM into cut start times for a 30-second Short. Runnable Python, plus the $0.10 Timeline render and $0.125 bed.
- Cut hold music from a call recording before STT: one concat job
Drop a hold-music stretch with one Sume timeline audio concat job that reuses the file twice via source_in and duration, then send the result to STT.
Written by Sume