Node --env-file for SUME_API_KEY: fail fast, not the string undefined
Node 22 loads .env with --env-file. A missing SUME_API_KEY then becomes the string 'undefined' in a header. Guard it in two lines and keep .env out of git.

Node 22 can load a dotenv file without a package: node --env-file=.env submit.mjs. It worked on Node 22.14.0 for a .env containing SUME_API_KEY and SUME_BASE. The trap is what happens when the variable is not there. process.env.SUME_API_KEY is undefined, and a header built from it is sent as the string undefined, which is not a credential. Verified in Node: new Request(url, { headers: { 'x-api-key': undefined } }) holds the value "undefined"; an empty variable holds the empty string.
Neither case is a useful error message at 2 a.m. Guard the variable first and stop with a sentence that names the cause.
submit.mjs (9 lines)
Sume accepts exactly one credential header. The SDK and CLI use x-api-key; sending both x-api-key and Authorization: Bearer returns 401 unauthorized (Send only one API key credential.). The script sends x-api-key only, and the job posts to /v1/videos. It ran against a local stand-in server that answers 202.
const key = process.env.SUME_API_KEY;
if (!key) throw new Error("SUME_API_KEY is empty: start with --env-file=.env or export it");
const res = await fetch(`${process.env.SUME_BASE ?? "https://api.sume.com"}/v1/videos`, {
method: "POST",
headers: { "x-api-key": key, "content-type": "application/json", "Idempotency-Key": "kite-env-1" },
body: JSON.stringify({ model: "wan-3.0", prompt: "a red kite", duration: 5, resolution: "480p" }),
});
console.log(res.status, (await res.json()).id);Run it
node --env-file=.env submit.mjs
# 202 job_17
node submit.mjs
# Error: SUME_API_KEY is empty: start with --env-file=.env or export itKeep the file out of git
The dashboard shows an API key's full secret only once, at creation, so the .env file is the only copy on that machine. Add .env to .gitignore before the first commit, keep production secrets in your platform's secret manager rather than a file, and rotate a key that was ever committed. Keys are workspace-scoped, so one leaked key exposes the whole workspace's balance.
Sources
Related posts
More in Developers
- Node: flip a video backend to Sume a day before the Veo 3.1 shutdown
Google ends three Veo 3.1 preview ids on Oct 22 and its page gives a date, not an hour. A 19-line Node switch moves traffic to Sume early, with an override.
- Node https.request: POST /v1/images on Sume, no fetch, no packages
Call Sume's image API from Node using only node:https: JSON body, bearer key, 40-second timeout that actually aborts, and 200 versus 202 handling.
- Omni draft grid: four 360p variants, then one final. What it costs
Google's Draft Room idea, run through the Sume API: four 8-second 360p drafts that change one thing each, then a 1080p final. Total $2.70, with a script.
- One Sume webhook signature, three languages: a shared test vector
A fixed secret, timestamp and body that must sign to the same sume-v1 value in Python, Node and Go. Use it to test a verifier in any language you add.
Written by Sume