Env and secrets diff for removing Sora: SUME_API_KEY, one auth header
Which environment variables to delete, add and rotate when a service leaves the OpenAI Videos API for Sume, plus a startup check that fails on a missing secret.

Moving a service off Sora and onto Sume changes five things in your environment: the key (SUME_API_KEY), the base URL (https://api.sume.com), the model value (a Sume catalog id or sume/auto), the clip-shape variables (duration, resolution and aspect ratio instead of seconds and size), and the webhook secret (SUME_COM_WEBHOOK_SIGNING_SECRET). Keep OPENAI_API_KEY only if the service still makes other OpenAI calls.
The OpenAI deprecations page, read 2026-10-08, lists the Videos API as removed on September 24, 2026, so any worker that still reads a Sora model variable is dead code with a live secret attached.
The diff in one table
Use this as the checklist for your secrets manager and your deploy config, not only the .env file.
| Old setting | New setting | Note |
|---|---|---|
| OPENAI_API_KEY, video workers only | SUME_API_KEY | server side only; it spends workspace credits |
| OpenAI base URL in client config | https://api.sume.com | the SDK default; dev is https://api.dev.sume.com |
| VIDEO_MODEL=sora-2 | a catalog id or sume/auto | any other model string answers 404 model_not_found |
| VIDEO_SECONDS="8" and VIDEO_SIZE | duration (integer), resolution, aspect_ratio | size is rejected with 400 unsupported_parameter |
| OpenAI webhook secret | SUME_COM_WEBHOOK_SIGNING_SECRET | dashboard webhooks page or GET /v1/webhooks/signing-secret |
One credential per request
Sume accepts Authorization: Bearer or x-api-key. Send one. A request with both is a 401 with the message Send only one API key credential, which is easy to hit when a proxy adds a header you also set in code. The SDK sends only x-api-key by default.
A key's scopes are fixed when you create it, so if a worker needs to read the webhook signing secret or send test deliveries it needs a key that was created with those scopes; you cannot add them afterward. Create a separate key per service so you can revoke one without touching the rest.
A startup check
Fail the deploy when a secret is empty, rather than discovering it on the first 401 or on an unsigned webhook. This runs on any Node version with process.env.
const required = ["SUME_API_KEY", "SUME_COM_WEBHOOK_SIGNING_SECRET"];
const missing = required.filter((name) => !process.env[name]);
if (missing.length > 0) {
console.error(`Missing environment variables: ${missing.join(", ")}`);
process.exit(1);
}
if (process.env.OPENAI_API_KEY && process.env.VIDEO_MODEL?.startsWith("sora")) {
console.error("VIDEO_MODEL still names a Sora model");
process.exit(1);
}
console.log("environment ok");Clean up
Revoke the OpenAI key for the video workers once the last Sora job has been reconciled, and remove the old variables from CI, staging and local templates in the same change so nobody copies them forward. The shutdown runbook puts this step last for a reason: do it after the new path has carried real traffic.
Sources
Related posts
More in Developers
- Extract 16 kHz mono audio from a video for transcription
A Python script that detaches speech-ready 16 kHz mono wav from a Sume-hosted video, then polls the job. Costs $0.01 per detach before the STT minute.
- Face swap request in Python: validate the video URL before you send
A Python snippet that rejects non-HTTPS, localhost and private-IP video URLs locally, then submits a Sume face-swap beta run with a quality and idempotency key.
- Failed Sume video job: resubmit or stop? Read retryable, next_action
Sora said failed and little else. A failed Sume job carries an error with category, retryable, retry_after_seconds and next_action. A small decision function.
- FastAPI 0.142 native OpenTelemetry: tag spans with a Sume job id
FastAPI 0.142.0 added native OpenTelemetry. Put the Sume job_id on the current span in a webhook route so a failed render shows up next to the HTTP trace.
Written by Sume