Expiring API keys: Sume key metadata and rotation habits
OpenAI added enforced key lifetimes in Sep 2026. Sume's docs list key id, name, prefix, scopes and last-used time, so rotate on a schedule you keep.

OpenAI's changelog says that on Sep 10, 2026 administrators can enforce maximum key lifetimes at the organization or project level. The Sume docs describe no expiration field, so on Sume you rotate on a schedule you keep yourself: create a replacement key, deploy it, verify with GET /v1/me, then revoke the old key.
What each side documents
The OpenAI column is from its API changelog; the Sume column is from the authentication docs.
| Item | OpenAI | Sume |
|---|---|---|
| Expiration | Admins can require new keys to expire within a configured maximum lifetime (Sep 10, 2026) | No expiration field in the docs |
| Governance | Org controls: service-account keys only, user-owned project keys only, or no new keys (Sep 15, 2026) | Keys are workspace-scoped |
| Metadata shown | Not covered here | Id, name, prefix, scopes and last-used time; never the full secret |
| Scopes | Not covered here | Fixed at creation; cannot be added later |
A rotation routine for Sume keys
Sume says to create a replacement key, deploy it to your server, verify GET /v1/me, then revoke the old key from the dashboard, and to rotate if a key appears in logs or chat history. Because scopes cannot be added to an existing key, rotating is also how you pick up a scope that did not exist when the key was made, such as formats:write or actions:write.
Send exactly one credential. A request carrying both an Authorization Bearer header and x-api-key is rejected with 401, so strip the one your gateway adds before you switch keys.
# 1. Verify the new key before you revoke the old one
curl https://api.sume.com/v1/me \
-H "Authorization: Bearer $NEW_SUME_API_KEY"
# 2. Revoke the old key in the dashboard once traffic is on the new oneUse last-used time as a check
The dashboard shows when each key was last used. After a deploy, the old key's last-used time should stop moving; if it does not, something is still calling with it, and revoking it would break that caller. Wait for the time to settle before you revoke.
- Name keys by service and rotation date so the list stays readable.
- Keep keys on servers and in CI secret stores, never in frontend code.
- Rotate on a fixed calendar, since there is no expiry to force it.
- A scope that is missing returns 403 insufficient_scope; the fix is a new key.
Sources
Related posts
More in Developers
- What to save from a Sume run when batch results expire at 30 days
OpenAI keeps batch output 30 days, Anthropic 29, Gemini 6 weeks. Which Sume run receipt fields to store so your records outlive any vendor retention window.
- isTerminalJobStatus vs isTerminalRunStatus: skipped only ends runs
The Sume SDK has two terminal checks. Jobs end on completed, failed or canceled; runs also end on skipped. Reusing one for both breaks a custom poll loop.
- Seedance 1.5 Pro retires Nov 11: pin a live Sume model id
ElevenLabs says ByteDance retires Seedance 1.5 Pro on Nov 11, 2026. Pin an id Sume's video catalog lists today and verify its limits first.
- Seedance 2.5 720p on fal, 1080p on Sume: read the catalog
fal lists Seedance 2.5 Image to Video at up to 720p and 30 seconds. Sume docs list seedance-2.5 at 4-30 s and 480p/720p/1080p. Check the catalog before pinning.
Written by Sume