Railway Sandboxes: run the Sume CLI with an env-var key

Inside a short-lived sandbox, install the Sume CLI with the hosted installer, pass SUME_API_KEY as an environment variable, and never print it.

4 min readSume
All posts

In a disposable sandbox, install the Sume CLI with curl https://cli.sume.com/install -fsS | bash, supply SUME_API_KEY from the platform's secret store as an environment variable, and do not echo it. Skip sume login there: browser approval is for local machines.

What Railway announced

The Railway changelog entry dated Sep 17, 2026 is titled "Railway Sandboxes, use your ChatGPT subscription with Railway Agent, MySQL PITR". This post relies only on that title. It does not describe sandbox limits or lifetimes, so check Railway's own documentation for them.

Install and verify

The Sume docs recommend the hosted installer for the native binary. It downloads the release for the OS and architecture, verifies it against checksums.txt, and installs sume under ~/.sume-com/bin without silently overwriting a different sume already on the PATH. The docs name Linux x64 and arm64 release assets, so a Linux sandbox is covered.

Pin a release tag when you need repeatable runs; the docs show replacing latest with a tag such as v0.1.6 in the GitHub release URL.

set -euo pipefail
curl https://cli.sume.com/install -fsS | bash
export PATH="$HOME/.sume-com/bin:$PATH"

# SUME_API_KEY comes from the sandbox's secret or env settings.
# Check without printing it.
test -n "${SUME_API_KEY:-}" || { echo "SUME_API_KEY is not set"; exit 1; }
sume version
sume doctor --agent --json

Key handling rules

The CLI security page lists what must never be printed or committed: SUME_API_KEY, the local ~/.sume-com/config.json, and raw provider payloads. Use environment variables or a secret manager for automation.

Manual API-key setup and environment variables are the documented path for CI and controlled server environments. x-api-key is the CLI default auth header; SUME_API_AUTH_MODE=bearer switches it.

Paid gates in a throwaway environment

Write commands need confirmation flags. --confirm-submit covers non-paid writes such as cancellation; --confirm-paid covers Avatar 1.0 and Avatar Video 1.0 runs that can reserve or spend credits. A sandbox that disappears after the command makes recovery harder, so record the job id before the sandbox exits and recover existing jobs instead of re-running paid commands.

CLI install facts (read 2026-10-03)
QuestionAnswer
Install commandcurl https://cli.sume.com/install -fsS | bash
Install location~/.sume-com/bin
Integrity checkchecksums.txt
Headless sign-insume login --no-browser, or an env-var key

Sources

Related posts

More in Developers

All Developers posts

Written by Sume