Node --env-file for SUME_API_KEY: fail fast, not the string undefined

Node 22 loads .env with --env-file. A missing SUME_API_KEY then becomes the string 'undefined' in a header. Guard it in two lines and keep .env out of git.

4 min readSume
All posts

Node 22 can load a dotenv file without a package: node --env-file=.env submit.mjs. It worked on Node 22.14.0 for a .env containing SUME_API_KEY and SUME_BASE. The trap is what happens when the variable is not there. process.env.SUME_API_KEY is undefined, and a header built from it is sent as the string undefined, which is not a credential. Verified in Node: new Request(url, { headers: { 'x-api-key': undefined } }) holds the value "undefined"; an empty variable holds the empty string.

Neither case is a useful error message at 2 a.m. Guard the variable first and stop with a sentence that names the cause.

submit.mjs (9 lines)

Sume accepts exactly one credential header. The SDK and CLI use x-api-key; sending both x-api-key and Authorization: Bearer returns 401 unauthorized (Send only one API key credential.). The script sends x-api-key only, and the job posts to /v1/videos. It ran against a local stand-in server that answers 202.

const key = process.env.SUME_API_KEY;
if (!key) throw new Error("SUME_API_KEY is empty: start with --env-file=.env or export it");

const res = await fetch(`${process.env.SUME_BASE ?? "https://api.sume.com"}/v1/videos`, {
  method: "POST",
  headers: { "x-api-key": key, "content-type": "application/json", "Idempotency-Key": "kite-env-1" },
  body: JSON.stringify({ model: "wan-3.0", prompt: "a red kite", duration: 5, resolution: "480p" }),
});
console.log(res.status, (await res.json()).id);

Run it

node --env-file=.env submit.mjs
# 202 job_17
node submit.mjs
# Error: SUME_API_KEY is empty: start with --env-file=.env or export it

Keep the file out of git

The dashboard shows an API key's full secret only once, at creation, so the .env file is the only copy on that machine. Add .env to .gitignore before the first commit, keep production secrets in your platform's secret manager rather than a file, and rotate a key that was ever committed. Keys are workspace-scoped, so one leaked key exposes the whole workspace's balance.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume