GitHub Actions and Sume: secret setup and a smoke test
Store SUME_API_KEY as a GitHub Actions secret, never echo it, and run sume account get --json as a read-only smoke test in a manually triggered workflow.

Add SUME_API_KEY as a repository secret, map it into the step's environment, and run sume account get --json as a read-only check. The GitHub changelog lists stateless GitHub App installation tokens rolling out on Oct 2, 2026, and Actions retention now covering checks, runs and statuses as of Oct 1, which makes it more important to keep secrets out of logs.
Setup
Create a key in the Sume API Keys dashboard, then add it under the repository's Actions secrets. The CLI docs say never to print or commit SUME_API_KEY, the local config file or raw provider payloads, and to use environment variables or a secret manager for automation.
A smoke-test workflow
The workflow installs the CLI with the hosted installer, which places sume under ~/.sume-com/bin, then reads the account with output sent to /dev/null, so nothing sensitive reaches the log:
name: sume-smoke
on: workflow_dispatch
jobs:
smoke:
runs-on: ubuntu-latest
steps:
- name: Install Sume CLI
run: curl https://cli.sume.com/install -fsS | bash
- name: Check the key
env:
SUME_API_KEY: ${{ secrets.SUME_API_KEY }}
run: |
"$HOME/.sume-com/bin/sume" account get --json > /dev/null
echo "Sume key accepted"Keep CI from spending money
Keep the smoke test read-only. The CLI gates paid Avatar runs behind --confirm-paid, and the docs advise submitting one bounded job first when testing and recovering existing jobs instead of blindly retrying paid commands.
- Trigger by hand with
workflow_dispatchwhile you test - Do not pass
--confirm-paidin a smoke test - Do not echo the key or the account response
- Rotate the key if it ever appears in a log
Going beyond the smoke test
Image, video and music calls are API-first, so apply the same confirmation habits in your HTTP client. A workflow that submits paid jobs should use an Idempotency-Key per job and record the job id as an artifact, so a re-run recovers the job instead of paying twice.
Sources
Related posts
More in Developers
- A Go client for Sume from OpenAPI, with Retry-After
The docs list only a TypeScript SDK. Generate a Go client from the live OpenAPI schema, send x-api-key, and back off on 429 with retry-after.
- Google's June 15 deprecation notice gave 15 and 63 days: run a drill
Google announced Veo and Imagen 4 deprecations on Jun 15, 2026 with shutdowns Jun 30 and Aug 17. Here is a five-step drill that fits inside the shorter window.
- GPT Image 2.5 returns base64; Sume returns a URL: port the code
OpenAI's image API returns base64 data for GPT Image models, and Sume's returns hosted URLs. The three lines that change when you move a decoder over.
- Grok Imagine video API: 15 s, 5 references, request-ID polling
xAI's video guide for grok-imagine-video-1.5 lists up to 15 seconds, up to 5 reference images and async polling by request ID. The same loop on Sume jobs.
Written by Sume