Deno 2.9.7: scope permissions to a Sume key check on GET /v1/me
Run a Sume API key check in Deno 2.9.7 with allow-net limited to api.sume.com and allow-env limited to the key, and see what the permission error looks like.

To check a Sume API key from Deno, run deno run --allow-net=api.sume.com --allow-env=SUME_API_KEY on a script that calls GET /v1/me with the key in an Authorization: Bearer header. A 200 means the key works; a 401 means it was rejected, which the authentication docs say can also happen if you send two credential headers at once. The permission flags are the point: the script can reach one host and read one variable, and nothing else.
Deno 2.9.7 is the latest release on the Deno releases page at the time of writing, published September 16, 2026, with notes about certificate stores, HTTP authority caching and Node compatibility. None of that changes the permission model used here, so the same script runs on the 2.9 line.
Why scope the flags
A key check is the smallest useful call you can make to Sume, which makes it a good first script in a new project or pipeline. Granting it --allow-net without a host, or --allow-all, defeats the reason to use Deno. With the flags below, a bug or a bad dependency cannot send your key to another host, because the runtime refuses the connection. When we pointed a copy of the script at a local test server while allowing only api.sume.com, Deno stopped the request with a NotCapable error that names the blocked address.
| Item | Value | Source |
|---|---|---|
| Latest Deno release at time of writing | v2.9.7, Sep 16, 2026 | Deno releases |
| Network permission | --allow-net=api.sume.com | Deno flag, tested |
| Environment permission | --allow-env=SUME_API_KEY | Deno flag, tested |
| Key check route | GET /v1/me | Sume docs |
| Both Bearer and x-api-key sent | 401, send only one credential | Sume docs |
Steps
- Export
SUME_API_KEYin the shell that runs the script. Deno reads it only if you allow that name. - Run the script once in CI after a key rotation and once on a developer machine, so both paths are known to work before a paid job depends on them.
- Fail early on an empty key. An empty
Authorizationvalue looks like a server problem and wastes time. - Add a timeout with
AbortSignal.timeoutso the check cannot hang a CI step. - If you add a later step that downloads finished media, widen
--allow-netdeliberately for that script only; a result URL can point to a different host than the API.
Script
Save it as check-key.ts. It sends one credential and exits with a distinct code for an empty key (2), a rejected key (1) or an unexpected status (1).
// deno run --allow-net=api.sume.com --allow-env=SUME_API_KEY,SUME_BASE check-key.ts
const base = Deno.env.get("SUME_BASE") ?? "https://api.sume.com";
const apiKey = Deno.env.get("SUME_API_KEY") ?? "";
if (!apiKey) {
console.error("SUME_API_KEY is empty");
Deno.exit(2);
}
const res = await fetch(`${base}/v1/me`, {
headers: { Authorization: `Bearer ${apiKey}` },
signal: AbortSignal.timeout(10_000),
});
if (res.status === 401) {
console.error("key rejected (401): send only one credential header and check the key");
Deno.exit(1);
}
if (!res.ok) {
console.error(`unexpected ${res.status}`);
Deno.exit(1);
}
console.log("key ok", res.status);What Sume does not do
GET /v1/me confirms that a key authenticates; it does not tell you that the key has the scopes for every route you plan to use, and it does not check your balance. Use GET /v1/balance for credits, and see the quick start for creating a key. Sume also does not provide a Deno-specific client; the TypeScript SDK needs only fetch and WebCrypto.
Sources
Related posts
More in Developers
- Deno: a 30-second Wan 3.0 video with fetch and top-level await
A short Deno script that submits a 30-second wan-3.0 job, polls to completion and writes clip.mp4, using only fetch and no npm packages.
- Deploy check: does your video model id and duration exist on Sume?
A Python preflight that reads GET /v1/videos/models and fails the deploy when VIDEO_MODEL is not a catalog id or the duration is outside supported_durations.
- Derive the Idempotency-Key from a SHA-256 of the request in Python
A key built from the path and a canonical body hash makes a retry return the original Sume job and a changed prompt a new one, with no 409 to handle.
- Detach 16 kHz mono audio from a 25-minute video: 2 ranges, 2 cents
A 25-minute video exceeds audio detach's 900-second output cap, so request two 750-second ranges at 16 kHz mono: two jobs at $0.01 each, about 24 MB per wav.
Written by Sume