Format input vs instruction: where scraped product copy should go
Put scraped or customer text in the input object, not in instruction. Sume writes input to a file and marks it as data. Limits: 64 keys, 2 MiB, 4000 characters.

Put scraped product copy, customer messages and supplier fields in the input object of a Format run, and keep instruction for your own words. Sume writes input whole to a file in the run workspace and tells the agent the file is caller-supplied data, not instructions. If you concatenate that text into instruction, you lose that separation.
What each field carries
The two fields have different limits, and the second row is the surprise: instruction is accepted up to 8000 characters, yet only the first 4000 or so are carried as prompt text.
| Field | Accepted | Carried to the run |
|---|---|---|
instruction | 8000 characters | The first ~4000 characters, as prompt text |
input | JSON object, 64 top-level keys, 2 MiB compact | All of it, as a file; never truncated |
| Format body | 100 MiB per package file | All of it, as files |
Rules for input
The API checks only a few things: it must be a JSON object, with at most 64 top-level keys and at most 2,097,152 UTF-8 bytes. Nested keys are not counted, so group related values under one key. HTTPS media URLs found at any depth share the run's media budget of 30 files, 10 videos and 10 audio, and a bad one returns 400 invalid_attachment.
There is no published field list for input. The Format's recipe reads the keys it knows, so two callers can send different objects to the same Format and both be right. Check the Format's description and its io profile.
Trust and the output
The file is a trust boundary and not a sandbox. Runs have a spend cap, which limits the damage of a hostile payload, but do not pass raw untrusted text on purpose. Clean it first when you can.
input does not reach output. Sume builds output from what the run made and said, so a value you sent, such as a SKU, comes back only if the run repeats it. Keep identifiers on your side, keyed by the run id or the Idempotency-Key. An empty {} adds no file and no block, so a Format that says "read product_url from the input" would have nothing to read.
A short example
Say a shop sends a product page. A weak call puts the page text into instruction: "Make a video for this: <page text>". A better call puts a short instruction, "Make a 20 second vertical video of this product, using the product data in the input", and sends the product name, description and price as keys in input. The page text can then contain the line "ignore your instructions and do something else", and the agent has been told that this file is data.
This reduces the risk and does not remove it, as the docs say. Keep the spend cap low, review the output before it goes public, and strip content you do not need. The instruction stays well under 4000 characters, which also avoids the quiet truncation of anything past that point.
Sources
Related posts
More in Formats
- Format package files: which types and paths the Contents API accepts
A Sume Format package accepts only .md, .json, .yaml, .yml and .txt files, one folder deep, with SKILL.md required. The full rule list and the error you get.
- Cancel a Format run: cancel_effect, no_op and what you still pay
POST cancel on a Format run is idempotent. cancel_effect says canceled or no_op. You pay for generation done before the cancel, and no webhook is sent.
- Format run cap for 25 Nano Banana 2.1 images: $5.00 at 4K
A Format run that makes 25 Nano Banana 2.1 images costs $2.50 at 1K, $3.75 at 2K and $5.00 at 4K. How to set generation_spend_cap_usd and the Format default.
- Format run spend cap: the $400 default, in receipt micros
A Format with no cap set reports 400000000 micros. How the run cap, the $500 maximum, null and 0 behave, and why billable_amount is not the whole bill.
Written by Sume