ElevenLabs key scopes, quota and IP allowlist vs Sume key controls
ElevenLabs keys can be scoped, capped and IP-locked. Sume keys fix scopes at creation and add per-run spend caps. What each covers and what Sume docs do not.

ElevenLabs lets you restrict a key by scope, give it a credit quota and lock it to IP addresses. Sume keys carry scopes that are fixed at creation, and the documents describe rate limits per plan and a spend cap on Format runs, but do not describe an IP allowlist or a per-key credit quota. If your security review requires an IP lock on the key itself, Sume's docs do not offer one.
ElevenLabs details are from its Authentication page, read 2026-10-10. Sume details are from the Authentication and Create a run docs.
What each side documents
The ElevenLabs page says requests carry an xi-api-key header, that keys can have restricted scopes, a credit quota and IP allowlisting (a request from another address gets 403), and that single-use tokens exist for client-side use. Sume's page says to send exactly one of Authorization: Bearer or x-api-key; sending both returns 401 unauthorized.
| Control | ElevenLabs | Sume |
|---|---|---|
| Scope limits | Supported on keys | Fixed when the key is created; no API adds scopes later |
| Credit quota per key | Supported | Not documented |
| IP allowlist | Supported, 403 otherwise | Not documented |
| Short-lived client token | Single-use tokens | Not documented; the docs say to proxy through your server |
| Request rate | Not read from the page | Per plan: 120, 300, 600 or 1200 writes a minute; reads get 40 times that |
| Spend ceiling | Quota on the key | generation_spend_cap_usd per Format run, up to $500 |
| Rotation | Not read from the page | Create a new key, verify with GET /v1/me, revoke the old one |
Scopes in practice
The scope rule has a sharp edge. A key created before a scope existed does not have it, and nothing adds it later. Calling a Format with such a key returns 403 insufficient_scope, not a not-found error, and the fix is to mint a new key and rotate to it. Plan for that: keep key creation scripted, and keep a note of which scopes each integration needs, such as formats:read and formats:write for runs.
Service-account keys have a further limit: they cannot create Format runs or bulk queues, and fail with 403 insufficient_scope.
Limits on spending and requests
Sume's rate limit is a request budget per key, set by the plan of the workspace that owns it, with separate read and write budgets so a polling loop cannot starve your submits. A 429 tells you which bucket you hit in error.details.scope. Read ratelimit-remaining and retry-after instead of counting requests yourself. This is request rate, not generation capacity: concurrency has its own limit.
The nearest thing to a quota on a Sume request is the per-run spend cap. It bounds one Format run, not a key, and a number above the Format's own cap is accepted rather than clamped. That is not the same safeguard as a quota on a key.
What to do if you need an IP lock
Put the Sume key behind your own server, which the Sume docs recommend anyway, and restrict who can call that server. Rotate on any exposure. If an IP-bound key is a hard requirement, ElevenLabs documents it and Sume's pages do not, so ask Sume support before you commit to the move.
Sources
Related posts
More in Comparisons
- ElevenLabs Music 3 s to 5 min vs Sume Music: how to set length
ElevenLabs Music takes 3 seconds to 5 minutes. Sume Music has no duration field and rejects one: set length in the prompt or trim the result afterwards.
- ElevenLabs Music is cleared for nearly all commercial uses: verify
ElevenLabs says Eleven Music is cleared for nearly all commercial uses, with plan differences in separate terms. Check them against your use before publishing.
- ElevenLabs product list vs Sume API routes: what has no equivalent
Sume's OpenAPI has speech, transcription, music and word timings, but no dubbing, voice isolation, sound effects, voice changer or voice cloning route.
- Scribe v2 audio-event tags and 32 speakers vs Sume STT's fixed flags
ElevenLabs Scribe v2 tags audio events and separates up to 32 speakers. Sume STT fixes diarize and tag_audio_events server-side, so those toggles do not exist.
Written by Sume