falrun.com firewall allowlist vs Sume API and media hosts
fal says to allow fal.run, queue.fal.run and the falrun.com backups. For Sume, allow api.sume.com and media.sume.com; webhooks come to your own HTTPS host.

fal's reliability page lists backup domains (falrun.com for fal.run, queue.falrun.com for queue.fal.run) and says to allow HTTPS to both primary and backup if your network restricts outbound connections. For Sume, the docs name two hosts for programmatic use: api.sume.com for the API and media.sume.com for generated media.
Hostnames are from fal's Reliability page and Sume's Core workflow, read 2026-10-01. This post covers the hostnames the docs name, not IP ranges.
Which fal domains does the allowlist need?
Both columns of fal's table. The backup is used when the primary is unreachable, with the same API key, path, query parameters and body. fal also notes that token requests to rest.fal.ai and uploads to v3.fal.media have no backup domains.
Which hostnames does Sume use?
The Core workflow page lists api.sume.com as the public Developer API (/v1) and OpenAPI, and media.sume.com as first-party generated media artifacts. The dashboard lives under www.sume.com. The docs do not describe a backup API domain, so there is nothing equivalent to falrun.com to add.
| Host | Purpose in the docs |
|---|---|
api.sume.com | Public Developer API (/v1) and OpenAPI |
media.sume.com | First-party generated media artifacts |
www.sume.com | Dashboard and operator pages |
What about webhook traffic coming back?
That direction is your host, not Sume's. Webhook URLs must be public HTTPS URLs; localhost, private-network and non-HTTPS URLs are rejected. So an inbound firewall rule belongs on your receiver. See webhook URL rejected. If you cannot expose a receiver, poll the job instead.
How do I check the allowlist works?
From inside the restricted network, request https://api.sume.com/reference/json (the OpenAPI document, per the docs), then open a generated media.sume.com URL. Both must succeed over HTTPS.
Sources
Related posts
More in Developers
- fal generation_timeout 504 error: what to do on Sume
fal returns generation_timeout as a 504 typed error. Sume has a generation_timeout category; the documented action is to poll status or retry later.
- fal queue status IN_QUEUE IN_PROGRESS COMPLETED on Sume
Sume's status endpoint returns a queue-shaped status field with IN_QUEUE, IN_PROGRESS, COMPLETED, FAILED and CANCELED, mapped one-to-one onto sume_status.
- x-fal-billable-units header: WebSocket billing vs Sume receipts
fal bills WebSocket sessions via x-fal-billable-units headers. Sume has no such header: cost is a per-job ledger row you read back by job or run.
- x-fal-needs-retry header: what Sume uses to signal a retry
fal marks retryable errors with X-Fal-Needs-Retry. Sume signals retry through error category and code, retry-after on 429, and the same idempotency key.
Written by Sume