How to get an AI video generation API key: Sume steps and gotchas

Create a workspace API key in the Sume dashboard, send it as one header, check it with GET /v1/me, and keep it on your server. Scopes are fixed at creation.

4 min readSume
All posts

To get a Sume API key, create one in the API Keys dashboard, keep it in a server-side environment variable, and send it as either a Bearer token or an x-api-key header, but not both. Check it with GET /v1/me before you build anything on it.

Autocomplete for the query 'ai video generation api' offered completions such as key, key free and pricing when fetched on 2026-10-03, so this post answers the key question directly.

Steps

  • Create a key in the dashboard. Keys are workspace-scoped.
  • Store it as SUME_API_KEY in your server environment.
  • Call GET https://api.sume.com/v1/me to confirm it works.
  • Submit work to a generation endpoint with an Idempotency-Key header.

Sending the key

Both forms below are accepted by the current API. Use one consistently in each integration.

export SUME_API_KEY="sume_live_..."

curl https://api.sume.com/v1/me \
  -H "Authorization: Bearer $SUME_API_KEY"

# or
curl https://api.sume.com/v1/me \
  -H "x-api-key: $SUME_API_KEY"

Gotchas from the docs

API key gotchas stated in the Sume authentication docs (read 2026-10-03)
GotchaWhat happens
Sending both headers401 unauthorized with the message 'Send only one API key credential.' Neither header wins.
Scopes added laterNot possible. Scopes are fixed at creation; there is no API to patch them onto an existing key.
Old key, newer featureA key created before a scope existed returns 403 insufficient_scope, not a 404.
Workspace fields in bodiesDo not send workspace_id or user_id; the key resolves them.
Full secret in responsesNever returned; responses show id, name, prefix, scopes and last-used time.

Keep the key off the client

Browser and mobile apps should call your own backend, and your backend should attach the key. The docs show a server route that forwards the body to a Sume endpoint with the key and a fresh Idempotency-Key, after you validate input and enforce your own authorization.

Do not put the key in a prompt or a chat. If one appears in a log or a transcript, rotate it.

What happens on the first paid request

A valid submit is accepted as a durable job and returns an id. It may start at once or wait in queued until a concurrency slot opens. Balance is reserved at accept time. If it cannot be reserved the submit fails with 402 insufficient_credits before any provider work starts.

Then poll GET /v1/jobs/:id/status or take a signed webhook, and fetch the result when it is ready. A client timeout does not cancel the job.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume