Format run media URLs never expire and anyone can open them
Media from a Sume Format run lives at durable media.sume.com URLs that anyone with the link can open. What that means for per-customer access and retention.

The media URLs that a Sume Format run returns are durable media.sume.com HTTPS URLs. They do not expire, and each person who has the URL can open it. If your product needs per-customer access control, proxy the file or copy it into storage you control. Do not treat the URL as a secret.
What the docs say
This comes from the Runs and results page, in the receipt section. It is a property of the URL, and not of the key that made the run. A run's media, spend and history belong to the key that called it, but the file at its URL is open to anyone who learns the address.
| Property | Value |
|---|---|
| Host | media.sume.com, HTTPS |
| Lifetime | Does not expire |
| Who can open it | Anyone who has the URL |
| Where listed | artifacts[].url, primary_output_url, and media fields in output |
| Metadata alongside | content_type, size_bytes, width, height, duration_ms, checksum_sha256 |
What to do for a customer product
Three options cover most products. Pick by how private the file must be.
- Share the URL as is when the video is meant to be public, such as an ad or a listing tour.
- Copy the file into your own bucket and serve it with your own signed links when only one customer should see it. Use
checksum_sha256to confirm the copy is intact. - Keep the Sume URL out of logs, emails and analytics for private work, since it works for whoever reads those.
Related details
A receipt's artifacts[] is filled only once the run is terminal, and it is also filled on failures, so a failed run's partial media is still there. The metadata lets you check a file without downloading it, for example size and dimensions before you upload to an ad platform.
Your own references go the other way: media you send in input or attachments must be HTTPS URLs, and they share a 30-file budget per run. Use a URL that stays reachable for the length of the run.
A copy step in code terms
If you copy files, do it in the handler that receives the webhook, after you verify the signature and store the event. Read artifacts[] for the URLs, download each file, check checksum_sha256 and size_bytes against what you saved, and then write the path to your own database. Answer the webhook 2xx first, within 10 seconds, and do the copy afterward in a job, because a slow download inside the handler can cause a retry.
Since the URLs do not expire, a copy job can fail and run again later without a deadline from Sume. That removes one source of pressure from the design. It does not remove your own retention duties: deleting your copy does not remove the file at the Sume URL, so ask Sume support if you must remove one, and include the request_id and the run id.
Sources
Related posts
More in Formats
- Format run spend caps: $400 default, $500 maximum, and what null does
How Sume Format run spend caps work: the $400 platform default, a per-run generation_spend_cap_usd up to $500, null for $500, and 0 or above 500 as a 400.
- Format webhook: 10 s timeout, 10 attempts, about 3 h 5 min of retries
A slow Format webhook gets 10 tries. Without jitter, the last starts 11,010 s after the first; with 10 s timeouts the span is about 3 h 5 min. Code included.
- Format webhook outcome: ok, degraded or error, and what to do
The format.run.terminal webhook has three outcomes. Verify the sume-v1 signature, then branch: ok uses output, degraded uses artifacts, error is a failed run.
- Restyle last year's holiday clip with the Sume restyle Format
Reuse a holiday video you own with a new look. The Sume restyle Format keeps motion and cuts and changes the style; it does not swap a person or product.
Written by Sume