Env and secrets diff for removing Sora: SUME_API_KEY, one auth header

Which environment variables to delete, add and rotate when a service leaves the OpenAI Videos API for Sume, plus a startup check that fails on a missing secret.

4 min readSume
All posts

Moving a service off Sora and onto Sume changes five things in your environment: the key (SUME_API_KEY), the base URL (https://api.sume.com), the model value (a Sume catalog id or sume/auto), the clip-shape variables (duration, resolution and aspect ratio instead of seconds and size), and the webhook secret (SUME_COM_WEBHOOK_SIGNING_SECRET). Keep OPENAI_API_KEY only if the service still makes other OpenAI calls.

The OpenAI deprecations page, read 2026-10-08, lists the Videos API as removed on September 24, 2026, so any worker that still reads a Sora model variable is dead code with a live secret attached.

The diff in one table

Use this as the checklist for your secrets manager and your deploy config, not only the .env file.

Environment changes, Sume docs read 2026-10-08
Old settingNew settingNote
OPENAI_API_KEY, video workers onlySUME_API_KEYserver side only; it spends workspace credits
OpenAI base URL in client confighttps://api.sume.comthe SDK default; dev is https://api.dev.sume.com
VIDEO_MODEL=sora-2a catalog id or sume/autoany other model string answers 404 model_not_found
VIDEO_SECONDS="8" and VIDEO_SIZEduration (integer), resolution, aspect_ratiosize is rejected with 400 unsupported_parameter
OpenAI webhook secretSUME_COM_WEBHOOK_SIGNING_SECRETdashboard webhooks page or GET /v1/webhooks/signing-secret

One credential per request

Sume accepts Authorization: Bearer or x-api-key. Send one. A request with both is a 401 with the message Send only one API key credential, which is easy to hit when a proxy adds a header you also set in code. The SDK sends only x-api-key by default.

A key's scopes are fixed when you create it, so if a worker needs to read the webhook signing secret or send test deliveries it needs a key that was created with those scopes; you cannot add them afterward. Create a separate key per service so you can revoke one without touching the rest.

A startup check

Fail the deploy when a secret is empty, rather than discovering it on the first 401 or on an unsigned webhook. This runs on any Node version with process.env.

const required = ["SUME_API_KEY", "SUME_COM_WEBHOOK_SIGNING_SECRET"];
const missing = required.filter((name) => !process.env[name]);

if (missing.length > 0) {
  console.error(`Missing environment variables: ${missing.join(", ")}`);
  process.exit(1);
}

if (process.env.OPENAI_API_KEY && process.env.VIDEO_MODEL?.startsWith("sora")) {
  console.error("VIDEO_MODEL still names a Sora model");
  process.exit(1);
}

console.log("environment ok");

Clean up

Revoke the OpenAI key for the video workers once the last Sora job has been reconciled, and remove the old variables from CI, staging and local templates in the same change so nobody copies them forward. The shutdown runbook puts this step last for a reason: do it after the new path has carried real traffic.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume