OS credential store vs sume login: where the key lives
Inngest v1.45.0 stores CLI OAuth credentials in the OS credential store. The Sume CLI stores its login key in ~/.sume-com/config.json; use env keys in CI.

Inngest v1.45.0 stores OAuth credentials in the operating system's credential store, while the Sume CLI stores the key from sume login in a local config file at ~/.sume-com/config.json. The Sume docs do not mention an OS keychain, so protect that file and use SUME_API_KEY from a secret manager in CI.
What Inngest changed
The Releasebot Inngest feed says v1.45.0 on September 17, 2026 added OAuth login for CLI and MCP clients, and that "OAuth credentials are stored in the operating system's credential store and refreshed automatically".
| Item | Entry |
|---|---|
| Date | Sep 17, 2026 |
| New | OAuth login for CLI and MCP clients |
| Storage | OS credential store, refreshed automatically |
Where Sume's CLI keeps the key
sume login opens the device approval page at www.sume.com/cli/login, waits for approval and stores a CLI-scoped API key in local config, by default under ~/.sume-com/config.json. SUME_CONFIG_DIR moves that directory for tests or isolated environments. The docs list SUME_API_KEY and the config file together as secrets that must never be printed or committed.
The login key is an API key, not an OAuth token pair, so there is no refresh step to rely on.
Practical rules
- Laptops: use
sume login, and keep the config directory out of backups and repositories. - CI and servers: set
SUME_API_KEYfrom a secret manager; do not runsume loginthere. - Headless machines: use
sume login --no-browserto print the approval URL. - Shared machines: set
SUME_CONFIG_DIRper user or per job. - Rotate a key from the API Keys dashboard if a config file leaks.
For hosted MCP, OAuth is the preferred path for interactive clients such as Cursor and Claude, and an API key stays available for automation. Which store your MCP client uses for its OAuth token is that client's choice.
Sources
Related posts
More in Developers
- Instagram Reels API: a 100-posts-per-24-hours publish budget
The Instagram content publishing API limits an account to 100 API-published posts per moving 24 hours. A tested Python queue that spreads batch output under it.
- IPv6-only webhook endpoint: test Sume delivery before launch
OpenAI's API now accepts IPv6 connections. If your webhook host is IPv6-only, prove Sume can reach it with POST /v1/webhooks/test-deliveries first.
- Keep your Sora-style create_video() call: map it onto Sume
Sora's seconds, size and input_reference become duration, resolution plus aspect_ratio, and a first frame. Here is that map as a Python wrapper over Sume.
- Korean karaoke captions: korean-ad and language ko on Sume
Burn Korean karaoke-style captions with style korean-ad and language ko on /v1/video-captions: one phrase at a time, the spoken word in a heavier weight.
Written by Sume