Setting up API calls in FlutterFlow for AI video

Set up a FlutterFlow API call with a Bearer header, make it private so it runs as a Firebase Cloud Function, and poll the video job with a second call.

5 min readSume
All posts

To set up an API call in FlutterFlow, define it with its method, URL, headers, variables, body and JSON paths, test it, then run it from an action in your app. For an API that needs a secret key, such as an AI video API, also turn on Make Private in the call's Advanced Settings, so FlutterFlow routes the call through Firebase Cloud Functions instead of from the app.

The FlutterFlow steps below come from its API Calls page, read 2026-09-28. The video API is Sume's; its facts come from the video generation and authentication docs. Sume has no FlutterFlow connector; this is a plain HTTPS call.

How do I set up the call that starts a video?

Create one API call for the submit. FlutterFlow's defaults already fit: a POST body defaults to application/json.

  • Method and URL: POST https://api.sume.com/v1/videos.
  • Headers: Authorization: Bearer <your key>, the static-token pattern FlutterFlow documents, and Idempotency-Key: [request_id], using its bracket syntax for a variable in a header.
  • Variables: prompt and request_id as Strings. Create the request id once per video the user asks for and reuse it on a retry, so the retry replays the same job instead of paying twice.
  • Body: JSON with the model and resolution fixed, e.g. {"model": "seedance-2", "prompt": "…", "resolution": "720p"}, then drag the prompt variable in to replace the prompt value, as FlutterFlow describes.
  • JSON paths: test the call, then add $.id (the job id) and $.status.
  • Advanced Settings: turn on Make Private and Require Authentication, save, then Deploy APIs.

Is a private API call safe for my API key?

It is the setting FlutterFlow provides for this. Its docs say making a call private "is helpful if it uses tokens or secrets you don't want to expose in your app" and that it "will route this API call securely via the Firebase Cloud Functions". Private calls deploy as a Cloud Function in your Firebase project, named ffPrivateApiCall by default, and need Firebase connected. Require Authentication forces the user to be signed in through Firebase Authentication (FlutterFlow).

Sume's side of the rule: keys never go in "mobile apps", and you should "enforce your own authorization" before a request reaches Sume (Authentication). Require Authentication only proves the user is signed in; any signed-in user can still run the call. Keep the model and resolution fixed in the body, and if you need per-user limits, put your own backend function in front instead, as in React Native API integration.

How do I check when the video is ready?

Video is asynchronous: the submit returns a job id at once, and generation "typically takes 30 seconds to several minutes". Add two more private calls and poll the first on a timer; the docs suggest "a reasonable polling interval (e.g., 30 seconds)" (Video generation). Leave Cache API Results off on the status call, since FlutterFlow caches repeat calls with the same arguments.

From FlutterFlow: API Calls and Sume's Video generation and Jobs and results docs, read 2026-09-28.
CallMethod and URLWhat to read
Start videoPOST https://api.sume.com/v1/videos$.id, $.status
Check statusGET https://api.sume.com/v1/videos/[job_id]$.status: pending, in_progress, completed, failed or cancelled
Get the fileGET https://api.sume.com/v1/jobs/[job_id]/resultOnly once status is completed: the artifact's media.sume.com URL; pick the path from a finished job's test response

Why not play the URL from the status call?

The status response lists unsigned_urls, and those need your API key, which the app must never have. The job result lists the file as a public media.sume.com URL instead, which the app can load without any key. Download a generated video explains the difference.

What are the limits?

  • Concurrency: your Sume plan caps how many jobs run at once, and extra jobs wait as queued. When the queue is also full, a submit fails with 429 queue_full (Generation admission).
  • Cost: each start call spends your balance at provider list × 1.25 (Video generation), whoever in your app pressed the button.
  • Cold starts: FlutterFlow says Min Instances of 0 minimizes costs, while a value above 0 keeps instances warm "but may incur additional costs" (FlutterFlow).
  • Push instead of polling: a private call only sends requests, and receiving a webhook needs a public HTTPS endpoint of your own. For a notification when the video is done, see Firebase push when a video is ready. Another no-code builder, Bubble, is covered in Bubble API Connector.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume