Deno 2.9.7: scope permissions to a Sume key check on GET /v1/me

Run a Sume API key check in Deno 2.9.7 with allow-net limited to api.sume.com and allow-env limited to the key, and see what the permission error looks like.

4 min readSume
All posts

To check a Sume API key from Deno, run deno run --allow-net=api.sume.com --allow-env=SUME_API_KEY on a script that calls GET /v1/me with the key in an Authorization: Bearer header. A 200 means the key works; a 401 means it was rejected, which the authentication docs say can also happen if you send two credential headers at once. The permission flags are the point: the script can reach one host and read one variable, and nothing else.

Deno 2.9.7 is the latest release on the Deno releases page at the time of writing, published September 16, 2026, with notes about certificate stores, HTTP authority caching and Node compatibility. None of that changes the permission model used here, so the same script runs on the 2.9 line.

Why scope the flags

A key check is the smallest useful call you can make to Sume, which makes it a good first script in a new project or pipeline. Granting it --allow-net without a host, or --allow-all, defeats the reason to use Deno. With the flags below, a bug or a bad dependency cannot send your key to another host, because the runtime refuses the connection. When we pointed a copy of the script at a local test server while allowing only api.sume.com, Deno stopped the request with a NotCapable error that names the blocked address.

Deno flags and Sume key-check behavior used here (read 2026-10-08)
ItemValueSource
Latest Deno release at time of writingv2.9.7, Sep 16, 2026Deno releases
Network permission--allow-net=api.sume.comDeno flag, tested
Environment permission--allow-env=SUME_API_KEYDeno flag, tested
Key check routeGET /v1/meSume docs
Both Bearer and x-api-key sent401, send only one credentialSume docs

Steps

  • Export SUME_API_KEY in the shell that runs the script. Deno reads it only if you allow that name.
  • Run the script once in CI after a key rotation and once on a developer machine, so both paths are known to work before a paid job depends on them.
  • Fail early on an empty key. An empty Authorization value looks like a server problem and wastes time.
  • Add a timeout with AbortSignal.timeout so the check cannot hang a CI step.
  • If you add a later step that downloads finished media, widen --allow-net deliberately for that script only; a result URL can point to a different host than the API.

Script

Save it as check-key.ts. It sends one credential and exits with a distinct code for an empty key (2), a rejected key (1) or an unexpected status (1).

// deno run --allow-net=api.sume.com --allow-env=SUME_API_KEY,SUME_BASE check-key.ts
const base = Deno.env.get("SUME_BASE") ?? "https://api.sume.com";
const apiKey = Deno.env.get("SUME_API_KEY") ?? "";
if (!apiKey) {
  console.error("SUME_API_KEY is empty");
  Deno.exit(2);
}
const res = await fetch(`${base}/v1/me`, {
  headers: { Authorization: `Bearer ${apiKey}` },
  signal: AbortSignal.timeout(10_000),
});
if (res.status === 401) {
  console.error("key rejected (401): send only one credential header and check the key");
  Deno.exit(1);
}
if (!res.ok) {
  console.error(`unexpected ${res.status}`);
  Deno.exit(1);
}
console.log("key ok", res.status);

What Sume does not do

GET /v1/me confirms that a key authenticates; it does not tell you that the key has the scopes for every route you plan to use, and it does not check your balance. Use GET /v1/balance for credits, and see the quick start for creating a key. Sume also does not provide a Deno-specific client; the TypeScript SDK needs only fetch and WebCrypto.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume