falrun.com firewall allowlist vs Sume API and media hosts

fal says to allow fal.run, queue.fal.run and the falrun.com backups. For Sume, allow api.sume.com and media.sume.com; webhooks come to your own HTTPS host.

4 min readSume
All posts

fal's reliability page lists backup domains (falrun.com for fal.run, queue.falrun.com for queue.fal.run) and says to allow HTTPS to both primary and backup if your network restricts outbound connections. For Sume, the docs name two hosts for programmatic use: api.sume.com for the API and media.sume.com for generated media.

Hostnames are from fal's Reliability page and Sume's Core workflow, read 2026-10-01. This post covers the hostnames the docs name, not IP ranges.

Which fal domains does the allowlist need?

Both columns of fal's table. The backup is used when the primary is unreachable, with the same API key, path, query parameters and body. fal also notes that token requests to rest.fal.ai and uploads to v3.fal.media have no backup domains.

Which hostnames does Sume use?

The Core workflow page lists api.sume.com as the public Developer API (/v1) and OpenAPI, and media.sume.com as first-party generated media artifacts. The dashboard lives under www.sume.com. The docs do not describe a backup API domain, so there is nothing equivalent to falrun.com to add.

Hosts to allow for outbound HTTPS, read 2026-10-01.
HostPurpose in the docs
api.sume.comPublic Developer API (/v1) and OpenAPI
media.sume.comFirst-party generated media artifacts
www.sume.comDashboard and operator pages

What about webhook traffic coming back?

That direction is your host, not Sume's. Webhook URLs must be public HTTPS URLs; localhost, private-network and non-HTTPS URLs are rejected. So an inbound firewall rule belongs on your receiver. See webhook URL rejected. If you cannot expose a receiver, poll the job instead.

How do I check the allowlist works?

From inside the restricted network, request https://api.sume.com/reference/json (the OpenAPI document, per the docs), then open a generated media.sume.com URL. Both must succeed over HTTPS.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume