Sume API keys are workspace-scoped: where do the charges land?

A Sume API key belongs to one workspace and is shown in full only once. Spend lands in that workspace; Action calls must use the Action billing workspace.

5 min readSume
All posts

Sume Developer API keys are workspace-scoped. The dashboard shows the full secret only when you create the key, and charges from calls made with it belong to the workspace the key was created in. For Actions, the call must use the Action billing workspace. Create one key per workspace and per integration so the Usage view stays readable.

What the docs say

The API keys dashboard page states that API keys are workspace-scoped and the full secret is shown only at creation, so you should store it in a secret manager immediately. The attribution doc adds that Action calls must use the Action billing workspace.

Why it matters for teams

A team workspace and a personal workspace are separate owners of money and resources. A key created for one does not borrow the other's balance. If an agency needs per-client billing, a key from that client's workspace is the unit; see Black Friday per client keys.

A naming scheme that helps

  • One key per integration: for example, the n8n flow and the Slack-triggered flow get separate keys
  • Put the owner and purpose in the key name
  • Rotate by creating the new key first, switching callers, then revoking the old one

Check before you ship

Call /v1/balance with the key to confirm which wallet it reads:

curl https://api.sume.com/v1/balance \
  -H "Authorization: Bearer $SUME_API_KEY"

Keys and connectors are different

A workspace integration like Slack is a token Sume holds for a workspace. An API key is a credential you hold. Disconnecting one does not revoke the other.

Common mistakes

Using a personal key in a team automation, so charges land in the wrong wallet. Reusing one key across several clients, so Usage cannot separate them. Pasting the secret into a chat or a repository, which forces a rotation.

The fix for all three is the same: one key per workspace and purpose, stored in a secret manager, and checked with a balance call before it goes live.

Related posts

More in Developers

All Developers posts

Written by Sume