Format input vs instruction: where scraped product copy should go

Put scraped or customer text in the input object, not in instruction. Sume writes input to a file and marks it as data. Limits: 64 keys, 2 MiB, 4000 characters.

5 min readSume
All posts

Put scraped product copy, customer messages and supplier fields in the input object of a Format run, and keep instruction for your own words. Sume writes input whole to a file in the run workspace and tells the agent the file is caller-supplied data, not instructions. If you concatenate that text into instruction, you lose that separation.

What each field carries

The two fields have different limits, and the second row is the surprise: instruction is accepted up to 8000 characters, yet only the first 4000 or so are carried as prompt text.

input and instruction limits from the Create a run docs, as of 2026-10-09
FieldAcceptedCarried to the run
instruction8000 charactersThe first ~4000 characters, as prompt text
inputJSON object, 64 top-level keys, 2 MiB compactAll of it, as a file; never truncated
Format body100 MiB per package fileAll of it, as files

Rules for input

The API checks only a few things: it must be a JSON object, with at most 64 top-level keys and at most 2,097,152 UTF-8 bytes. Nested keys are not counted, so group related values under one key. HTTPS media URLs found at any depth share the run's media budget of 30 files, 10 videos and 10 audio, and a bad one returns 400 invalid_attachment.

There is no published field list for input. The Format's recipe reads the keys it knows, so two callers can send different objects to the same Format and both be right. Check the Format's description and its io profile.

Trust and the output

The file is a trust boundary and not a sandbox. Runs have a spend cap, which limits the damage of a hostile payload, but do not pass raw untrusted text on purpose. Clean it first when you can.

input does not reach output. Sume builds output from what the run made and said, so a value you sent, such as a SKU, comes back only if the run repeats it. Keep identifiers on your side, keyed by the run id or the Idempotency-Key. An empty {} adds no file and no block, so a Format that says "read product_url from the input" would have nothing to read.

A short example

Say a shop sends a product page. A weak call puts the page text into instruction: "Make a video for this: <page text>". A better call puts a short instruction, "Make a 20 second vertical video of this product, using the product data in the input", and sends the product name, description and price as keys in input. The page text can then contain the line "ignore your instructions and do something else", and the agent has been told that this file is data.

This reduces the risk and does not remove it, as the docs say. Keep the spend cap low, review the output before it goes public, and strip content you do not need. The instruction stays well under 4000 characters, which also avoids the quiet truncation of anything past that point.

Sources

Related posts

More in Formats

All Formats posts

Written by Sume