How to get a public URL for an image an API can fetch
Host the image where anyone can fetch it over HTTPS without a login: a public storage object, a public bucket URL, or your own site. Then test it.

To get a public URL for an image, put the file somewhere that serves it over HTTPS to anyone, without a login: an object in a cloud storage bucket that you make public, a public bucket address, or a folder on your own website. Then open the URL from a browser or machine that isn't signed in to anything: if the image loads there, the URL is public.
Storage behavior below is quoted from Google Cloud's Make data public and Access public data, Amazon S3's Block Public Access and presigned URL guides, and Cloudflare's R2 public buckets page; the Sume rules come from its API reference and Media inputs docs. All were read on 2026-09-28.
Where can I host an image to get a public URL?
Any HTTPS host that answers without asking who you are. The common options, and the catch with each:
| Option | How you get the URL | Watch out for |
|---|---|---|
| Google Cloud Storage | Grant allUsers the Storage Object Viewer role on the bucket; the object is then at https://storage.googleapis.com/BUCKET_NAME/OBJECT_NAME | You can't share an object publicly if its bucket is subject to public access prevention |
| Amazon S3 | Change the bucket policy or object permissions to allow public access | New buckets and objects don't allow public access by default, and Block Public Access settings override policies that do |
| Amazon S3 presigned URL | Share with a presigned URL from the console, the AWS CLI or an SDK | Time-limited: at most 12 hours from the console and 7 days from the CLI |
| Cloudflare R2 | Enable the public development URL (an r2.dev subdomain) or connect a custom domain | r2.dev access is rate-limited and meant for development only; use a custom domain for production |
| Your own website | Put the file in a folder your site already serves over HTTPS | Pages behind a login or bot check won't work for a server |
How do I check that an image URL is really public?
Fetch it the way an API server would: from outside your network, with no cookies or credentials. A request for the headers alone is enough. You want a 200 status and a Content-Type that starts with image/; a redirect to a login page, a 403, or an HTML page means the server won't get the image either.
curl -sI https://storage.googleapis.com/BUCKET_NAME/product.png
# HTTP/2 200
# content-type: image/pngIs a public image URL permanent?
Only as long as you leave it public. Google's docs say anyone who knows a public object's URI can access it for as long as the object is public, so don't put anything private there. A presigned URL is the opposite trade: it grants time-limited access, and once it expires the link stops working, which matters if a job fetches the image later than you expect.
What kind of image URL does Sume accept?
A plain public HTTPS URL. Sume's generation requests take fetchable public HTTPS media URLs directly in the documented fields, such as an avatar photo's input.image_url, and reject localhost, private-network, non-HTTPS and non-image responses before the job is submitted (API reference). Its Media inputs page also lists signed or private URLs as rejected, so use a public object rather than a presigned link.
Sume's upload routes are hidden from its public OpenAPI, and the docs say to prefer public HTTPS media URLs, so host the file yourself as above. Sume's editing tools, such as trim and Timeline, work differently: they take files already on this workspace's media.sume.com, as Sume media URL rules by endpoint explains.
Sources
- Google Cloud Storage: Make data public (read 2026-09-28)
- Google Cloud Storage: Access public data (read 2026-09-28)
- Amazon S3: Blocking public access to your Amazon S3 storage (read 2026-09-28)
- Amazon S3: Sharing objects with presigned URLs (read 2026-09-28)
- Cloudflare R2: Public buckets (read 2026-09-28)
- API reference
- Media inputs
- Video trim
- Timeline 1.0
Related posts
More in Developers
- How to test an MCP server: Inspector, Postman, or curl
Test an MCP server with the MCP Inspector: connect, sign in or add an auth header, list tools, and call a read-only one. Postman and curl work too.
- HTTP 202 vs 201: created now, or accepted for later?
Return 201 Created when the resource exists by the time you respond, and 202 Accepted when the work will finish later. How 200, 201 and 202 differ.
- httpx timeout: the 5-second default and slow AI API calls
httpx times out after 5 seconds of network inactivity by default. How to set connect, read, write and pool timeouts for slow AI API calls.
- Is POST idempotent? No, but PUT and DELETE are
No. HTTP defines GET, HEAD, OPTIONS, TRACE, PUT and DELETE as idempotent, but not POST or PATCH. An idempotency key makes a POST retry safe.
Written by Sume