Sume API key scopes per call: formats, jobs, account, webhooks
Reading a Format run needs formats:read; cancel and redeliver need formats:write; the signing secret needs account:read. Scopes are fixed at key creation.

Sume API keys carry scopes that are fixed when the key is created, and a call without the right scope gets 403 insufficient_scope. Reads of Format runs need formats:read, cancel and redeliver need formats:write, and reading the webhook signing secret needs account:read.
You cannot add a scope to an existing key: there is no API to patch scopes onto a key, so an old key that predates a scope has to be replaced.
Which call needs which scope
Collected from the Sume authentication, webhook and Format run pages (read 2026-10-03).
| Call | Scope |
|---|---|
| Read a Format run, its status, result or events | formats:read |
| POST /v1/format-runs/{run_id}/cancel | formats:write |
| POST /v1/format-runs/{run_id}/webhook/redeliver | formats:write |
| POST /v1/jobs/{job_id}/webhook/redeliver | jobs:write |
| GET /v1/webhooks/signing-secret | account:read |
| POST /v1/webhooks/signing-secret/rotate | account:write |
| POST /v1/webhooks/test-deliveries | account:write |
| Action run requests | actions:read and actions:write |
The old-key trap
Keys created before a scope existed do not carry it. A pre-Formats key calling a Format gets 403 insufficient_scope, never 404 format_not_found, and a key older than the Actions API trigger returns 403 insufficient_scope on every Action run request. The fix is to create a new key and rotate to it.
Check what a key carries before you rely on it. GET /v1/me verifies the key and the workspace it resolves to, and responses expose key metadata such as id, name, prefix, scopes and last-used time, but never the full secret.
curl https://api.sume.com/v1/me \
-H "Authorization: Bearer $SUME_API_KEY"A least-privilege layout
Give the service that only reads dashboards a key with read scopes, give the receiver that redelivers webhooks jobs:write or formats:write, and keep account:write for the operator who rotates the signing secret. Separate keys also help with the job visibility rule: an API key reads only jobs its own member created, as in why a job returns 404. For a service-account failure, see 403 insufficient_scope on a Format run.
Sources
Related posts
More in Developers
- Sume API rate limits by plan: requests per minute for writes and reads
Sume gives every API key a per-minute budget set by plan: 120 writes on Free up to 1200 on Scale, with reads at forty times the write number. Table and headers.
- Sume hides provider names and task ids: what to debug with
Sume job responses and events are provider-neutral: no vendor task ids or raw URLs. The fields to debug a video job with instead.
- Sume Auto image aspect_ratio 21:9 returns 400: what to send
sume/auto rejects aspect_ratio 21:9 and lists nine accepted values. Use image_size, or pin a model that lists 21:9, such as Nano Banana Pro or Flux 2 Pro.
- sume/auto video returns 400 unsupported_capability: 2 s, 11 s, 480p
Why a sume/auto video request fails with 400 for 2 or 11 seconds, 480p, 768p or generate_audio false, and which pinned model takes the value instead.
Written by Sume