Format run media URLs never expire and anyone can open them

Media from a Sume Format run lives at durable media.sume.com URLs that anyone with the link can open. What that means for per-customer access and retention.

5 min readSume
All posts

The media URLs that a Sume Format run returns are durable media.sume.com HTTPS URLs. They do not expire, and each person who has the URL can open it. If your product needs per-customer access control, proxy the file or copy it into storage you control. Do not treat the URL as a secret.

What the docs say

This comes from the Runs and results page, in the receipt section. It is a property of the URL, and not of the key that made the run. A run's media, spend and history belong to the key that called it, but the file at its URL is open to anyone who learns the address.

Media URL properties from the Format docs, as of 2026-10-09
PropertyValue
Hostmedia.sume.com, HTTPS
LifetimeDoes not expire
Who can open itAnyone who has the URL
Where listedartifacts[].url, primary_output_url, and media fields in output
Metadata alongsidecontent_type, size_bytes, width, height, duration_ms, checksum_sha256

What to do for a customer product

Three options cover most products. Pick by how private the file must be.

  • Share the URL as is when the video is meant to be public, such as an ad or a listing tour.
  • Copy the file into your own bucket and serve it with your own signed links when only one customer should see it. Use checksum_sha256 to confirm the copy is intact.
  • Keep the Sume URL out of logs, emails and analytics for private work, since it works for whoever reads those.

Related details

A receipt's artifacts[] is filled only once the run is terminal, and it is also filled on failures, so a failed run's partial media is still there. The metadata lets you check a file without downloading it, for example size and dimensions before you upload to an ad platform.

Your own references go the other way: media you send in input or attachments must be HTTPS URLs, and they share a 30-file budget per run. Use a URL that stays reachable for the length of the run.

A copy step in code terms

If you copy files, do it in the handler that receives the webhook, after you verify the signature and store the event. Read artifacts[] for the URLs, download each file, check checksum_sha256 and size_bytes against what you saved, and then write the path to your own database. Answer the webhook 2xx first, within 10 seconds, and do the copy afterward in a job, because a slow download inside the handler can cause a retry.

Since the URLs do not expire, a copy job can fail and run again later without a deadline from Sume. That removes one source of pressure from the design. It does not remove your own retention duties: deleting your copy does not remove the file at the Sume URL, so ask Sume support if you must remove one, and include the request_id and the run id.

Sources

Related posts

More in Formats

All Formats posts

Written by Sume