OpenAI service-account-only keys, and Sume Format run limits
OpenAI admins can allow only service-account keys. On Sume, service-account keys cannot create Format runs or bulk queues; use a user-issued key.

OpenAI now lets administrators allow only service-account keys, only user-owned project keys, or no new keys at all. On Sume the key type matters differently: service-account keys cannot create Format runs or bulk queues and fail with 403 insufficient_scope. If your org standardizes on service accounts, plan a separate key for Formats.
The OpenAI rule is from its changelog (Sep 15 entry); the Sume rule is from Bulk runs, read 2026-10-01.
What did OpenAI change?
API key creation governance controls exist at organization and project level. Organization restrictions take precedence over project settings, and existing API keys are unaffected.
Which Sume keys can submit Format runs?
The bulk-runs page lists the auth rules: a Bearer API key, formats:write to create a queue and formats:read to poll it, a key issued in the owning workspace for team-owned Formats, and, last, that service-account keys cannot create Format runs or bulk queues. They fail with 403 insufficient_scope and details.reason of service_account_format_runs_unsupported.
| Requirement | Detail |
|---|---|
| Create a queue | formats:write |
| Poll a queue | formats:read |
| Team-workspace Format | Key issued in that workspace |
| Service-account key | service_account_format_runs_unsupported |
What if my key predates the scope?
Scopes are fixed when a key is created and cannot be added later. A pre-Formats key calling a Format gets 403 insufficient_scope, never 404 format_not_found. Create a new key. More on diagnosing this is in Format run 403.
Do key types change concurrency?
Not according to these pages. Workspace generation concurrency still applies to the child runs of a bulk queue, whichever user key created it. Size concurrency (1-16) with that in mind; see bulk Format runs.
Sources
Related posts
More in Developers
- Punch-in zoom on video by API: crop or zoompan, no keyframes
Sume has no auto zoom switch. Use a crop op for a fixed punch-in or the allowlisted zoompan filter in a video-filter graph; there are no keyframes.
- remove.bg API rate limit: 500 per minute, weighted by megapixels
remove.bg allows 500 images per minute at about 1 MP, less for larger inputs. Sume limits requests per minute per key and sends retry-after on 429.
- remove.bg bg_color replacement: Sume RMBG gives a transparent PNG
remove.bg's API has bg_color and bg_image_url. Sume RMBG 1.0 takes only an image_url and returns a PNG with alpha, so the new background is a second step.
- remove.bg crop and roi parameters: what Sume RMBG does instead
remove.bg has crop, roi, crop_margin, scale and position. Sume RMBG takes an image_url only and rejects other fields, so cropping happens before or after.
Written by Sume