Sume schedule run 403: a service-account key cannot start action runs
Starting a Sume schedule run with a service-account key fails with 403 insufficient_scope and service_account_action_runs_unsupported. Use a user API key.

You call POST /v1/actions/{action_id}/runs from a backend with a key you created for automation and get 403 insufficient_scope. Two different causes produce that status, and the body tells them apart.
Cause 1: missing scopes
Starting a run needs actions:read and actions:write. Keys created before the API-call trigger shipped do not have them, and you cannot add scopes to an existing key: create a new key at the dashboard and rotate to it (Advanced: run a schedule via API).
Cause 2: a service-account key
Service-account keys cannot create Action runs at all. They fail with 403 insufficient_scope and details.reason of service_account_action_runs_unsupported. New scopes will not fix that, so read details.reason before you rotate anything.
| Surface | Scope needed | Service-account key |
|---|---|---|
| Schedule run | actions:read and actions:write | Refused, service_account_action_runs_unsupported |
| Agent Completion | agent_completions:write | Refused, service_account_agent_completions_unsupported |
What to do
Create the key as a regular API key under the account that should own the runs, with the scopes above, and store it where your scheduler reads secrets. The Agent Completions page applies the same rule to its own endpoint, and also notes that completions are user-owned.
Log the request_id and details.reason from the response. A run that never started has nothing to cancel and spent nothing, so the retry is safe once the key is right.
Sources
Related posts
More in Developers
- Why sume/auto returns 400 for 21:9, not a Seedance route
sume/auto accepts 3 to 10 s in 16:9 or 9:16. Ask for 21:9 or 15 s and you get 400 unsupported_capability, not a quiet reroute to Seedance.
- sume/auto vs a pinned video model: three jobs where each wins
sume/auto is right for an 8-second 720p clip at $1.00. A 12-second or 20-second clip needs a pinned id, because auto resolves to Omni with a 10-second cap.
- Sume CLI avatar-videos batch: plan, create, watch, result
The Sume CLI batches avatar videos in four steps against local state files. What each step does, and why the per-item idempotency key makes reruns safe.
- Sume CLI quickstart: create an avatar video, follow it with jobs
Install the Sume CLI, log in, create a paid avatar video, and follow the job with sume jobs status, result and events. Why Image and Video have no CLI command.
Written by Sume