Embargoed Black Friday reveal: Sume media URLs are public, copy first

Format artifacts sit on durable public media.sume.com URLs with no expiry. For an embargoed drop, copy the file to your own storage and never log the URL.

3 min readSume
All posts

A finished Format artifact sits at a durable public URL on media.sume.com with expires_at: null. For an embargoed Black Friday reveal that matters: anyone who has the link can fetch the file, so treat the URL as the asset itself.

What the docs promise

  • The media URL does not expire.
  • Artifacts carry checksum_sha256, width, height and duration_ms so you can verify what you copied.
  • The cookbook's advice for products that embed a Format is server-only key custody, and to proxy or copy the durable URLs because they are public.

A copy-then-verify step

Fetch the artifact from result_url on your server, download it, compare the checksum and store it where your own access rules apply. Only then put your URL into the page that goes live at the embargo time.

import hashlib, requests

def copy_artifact(art, dest_path):
    data = requests.get(art["url"], timeout=60).content
    if hashlib.sha256(data).hexdigest() != art["checksum_sha256"]:
        raise ValueError("checksum mismatch")
    with open(dest_path, "wb") as f:
        f.write(data)

Keep it out of logs

Do not print the artifact URL in client-side code, error trackers or webhook logs before the reveal. Webhook bodies over 1 MiB arrive with payload: null and an error.result_url; fetch from your server in that case too. Remember that copying does not delete the public original.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume