OpenAI Agents API hosted sandbox: which Sume hosts to allow

OpenAI's Agents API is in public beta with hosted or connected sandboxes. Which Sume hosts to allow, how to pass the MCP URL, and why the key stays in a secret.

3 min readSume
All posts

OpenAI's changelog for September 10, 2026 lists the Agents API in public beta with durable sessions, running in OpenAI-hosted sandboxes or in a sandbox you connect. If a sandbox restricts outbound traffic, a Sume workflow needs three hosts: api.sume.com, mcp.sume.com and media.sume.com. Keep the Sume API key in a secret, not in the prompt.

What OpenAI announced

The only OpenAI fact this post relies on is the changelog line: Agents API public beta, durable sessions, and a choice of hosted sandbox or your own. The docs read for this post do not describe sandbox network rules, so check OpenAI's pages for how outbound access is configured.

Hosts to allow

The addresses below come from Sume's docs.

Sume hosts an agent sandbox may need (read 2026-10-03)
HostUsed for
api.sume.comREST API: jobs, videos, images, audio
mcp.sume.comHosted MCP at https://mcp.sume.com/mcp, plus OAuth metadata and consent
media.sume.comDurable artifact and asset URLs that generation returns and inputs reference

Connect Sume as a tool

If your agent runtime accepts a remote MCP server by URL, give it https://mcp.sume.com/mcp. For an unattended agent, use an API key sent as Authorization: Bearer <SUME_API_KEY> or x-api-key, because OAuth needs a person to approve consent in a browser. Sume's docs say an OAuth token is not an API key and should not be pasted into prompts.

Keep the key out of the prompt

Store the key in your platform's secret mechanism and inject it into the connection, not into the model's context. Safe logs hold request ids, job ids, high-level status and sanitized media metadata. Unsafe logs hold API keys, signed URLs and raw private media URLs. If a key shows up in a log or a transcript, rotate it.

Bound what the agent can spend

An API-key session sees write and paid tools, so set limits. Use dry_run=true or generation_admission_preview before the first paid submit, pass max_spend_usd to cap spend, and supply an idempotency_key on every paid call so a replayed step does not generate twice.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume