Sume schedule run 403: a service-account key cannot start action runs

Starting a Sume schedule run with a service-account key fails with 403 insufficient_scope and service_account_action_runs_unsupported. Use a user API key.

3 min readSume
All posts

You call POST /v1/actions/{action_id}/runs from a backend with a key you created for automation and get 403 insufficient_scope. Two different causes produce that status, and the body tells them apart.

Cause 1: missing scopes

Starting a run needs actions:read and actions:write. Keys created before the API-call trigger shipped do not have them, and you cannot add scopes to an existing key: create a new key at the dashboard and rotate to it (Advanced: run a schedule via API).

Cause 2: a service-account key

Service-account keys cannot create Action runs at all. They fail with 403 insufficient_scope and details.reason of service_account_action_runs_unsupported. New scopes will not fix that, so read details.reason before you rotate anything.

From docs.sume.com, read 2026-10-05
SurfaceScope neededService-account key
Schedule runactions:read and actions:writeRefused, service_account_action_runs_unsupported
Agent Completionagent_completions:writeRefused, service_account_agent_completions_unsupported

What to do

Create the key as a regular API key under the account that should own the runs, with the scopes above, and store it where your scheduler reads secrets. The Agent Completions page applies the same rule to its own endpoint, and also notes that completions are user-owned.

Log the request_id and details.reason from the response. A run that never started has nothing to cancel and spent nothing, so the retry is safe once the key is right.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume