Runway fails a redirected media URL; Sume follows up to five hops

Runway's API fails a media URL that answers 3XX. Sume follows up to 5 redirects if every hop is public HTTPS. Compare both URL rule sets before you port.

4 min readSume
All posts

Runway's API treats a media URL that answers with a redirect as a failed request, while Sume follows up to five redirects as long as every hop is a public HTTPS address. If your assets sit behind a link shortener, a CDN that 302s to a signed location, or a storage URL that redirects, that one rule decides whether your Runway inputs work and whether the same URL works on Sume.

Both sides are strict about other things too, and they are strict in different places. The tables below are from Runway's input page (read 2026-10-11) and from Sume's docs and code on origin/main.

Runway's URL rules

The Runway input page (read 2026-10-11) lists six rules for URL inputs. The URL must be HTTPS. It must use a domain name in the hostname, not an IP address. The server must return valid Content-Type and Content-Length headers. Redirects are not followed, and a 3XX response means the request failed. A single URL cannot exceed 2048 characters. The server must support HTTP HEAD requests.

The same page lists size limits for URL inputs of 16MB for images, 32MB for videos and 32MB for audio, with data URIs capped lower and ephemeral uploads at 200MB that are usable for 24 hours.

Sume's URL rules

Sume's Media inputs page says input image and video URLs must be fetchable public HTTPS URLs, and that before submission the API rejects localhost, private-network URLs, non-HTTPS URLs, signed or private URLs, and mismatched content types.

In the code, caller-supplied media reads go through a DNS-pinned public fetch that supports only GET and HEAD. It checks that each hop is a public HTTPS target and follows redirects up to PUBLIC_MEDIA_MAX_REDIRECTS = 5. A hop to a non-public target is a terminal error, and the sixth redirect fails with "Media URL redirected too many times." The default body cap in that fetch is 256MB. The video-filter docs also describe a HEAD source preflight that runs before an encode.

Side by side

Runway input page (read 2026-10-11) against Sume docs and public-media-fetch code on origin/main
RuleRunway APISume
HTTPS onlyYesYes
IP address in the URLNot allowed; domain name requiredPrivate-network targets are rejected on every hop
RedirectsNot followed; 3XX fails the requestFollowed up to 5 hops, each must be public HTTPS
HEAD supportServer must support HEADPreflight uses HEAD on some routes (video filter docs)
Signed or private URLsNot mentioned on the page I readRejected for these inputs per the docs
URL length2048 characters maximumNot stated in the docs I read

What breaks when you port

Two things break in opposite directions. A shortened or redirected URL that fails on Runway will work on Sume if it lands on a public HTTPS file within five hops. A presigned storage URL that works for you on Runway may be refused on Sume because signed and private URLs are rejected for these inputs, so put the file at a stable public HTTPS address instead.

Before you submit, request the URL with curl -I and read the final status, Content-Type and Content-Length. If you see a 3XX, replace it with the final location for Runway; for Sume, count the hops and make sure none leaves public HTTPS.

A quick check you can run

curl -sIL --max-redirs 5 https://example.com/clip.mp4 prints each hop's headers, so you can count redirects and see the content type on the last response.

Sources

Related posts

More in Comparisons

All Comparisons posts

Written by Sume