Recast photo URL rejected: public HTTPS, no login in the URL

A Recast request is refused when a reference photo URL is private, signed or carries a username and password. What Sume accepts and how to fix each case.

4 min readSume
All posts

The rule, from Sume's code

A Recast request needs one source video and between one and four reference photos. Sume checks every URL before the job exists. A URL passes only if it is public HTTPS and has no username or password in it. That check covers the source video and each photo, and a single bad photo fails the whole request.

The Media inputs page gives the same rule for the other launch endpoints: fetchable public HTTPS, with localhost, private-network, non-HTTPS and signed or private URLs rejected before generation starts.

Common ways a photo URL fails

Photo URL problems and fixes, from Sume's validation rules (read 2026-10-03)
URLWhy it failsFix
http://example.com/face.jpgNot HTTPSServe it over HTTPS
https://user:pass@example.com/face.jpgCredentials in the URLHost the file without basic auth
https://localhost/face.jpgNot publicUpload to a public host
Expiring signed storage linkSigned or private URLUse a stable public URL or a media.sume.com artifact
Link to an HTML pageContent type mismatchLink the image file itself

Count, order and prompt

The count must be between 1 and 4, one photo per new person. By default photos map to people left to right in the frame. The prompt is optional and capped at 2,000 characters; use it only to say who becomes whom or what else to keep.

fal's page, read 2026-10-03, says reference images are included at no extra charge, with the video billed at $0.30 per second at 768p or $0.45 at 1080p. On Sume, a fifth photo is an error, not an extra line item.

A request to copy

Replace both example URLs with files you can open in a private browser window without signing in. If you can, so can the worker.

curl -X POST https://api.sume.com/v1/video-router/generate \
  -H "Authorization: Bearer $SUME_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: recast-photo-check-001" \
  -d '{
    "model": "h3-max-recast",
    "video_url": "https://example.com/source.mp4",
    "reference_image_urls": ["https://example.com/host.jpg"],
    "duration": 10,
    "mode": "async"
  }'

How to test a URL before you submit

Open each URL in a private browser window. It should show the picture without a login, a redirect to a sign-in page, or a download prompt. Then run curl -I on it and confirm a 200 and an image content type. A host that blocks bots or returns an HTML page to non-browsers can pass the first test and fail the second.

If your photos live in private storage, copy them to a public location you control for the duration of the job. Sume rejects signed links by design, so a presigned URL will not do even if it works in your browser.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume