Authenticate the Sume CLI on a CI runner without a browser login
On CI, skip sume login: install the CLI, run sume auth setup with an API key from a secret, and confirm with sume auth status before any job step.

Run sume auth setup --api-key "$SUME_API_KEY" with the key injected from your CI secret store, then sume auth status. The browser flow is the recommended path for people; the docs say manual API-key setup and environment variables are still supported for CI and server automation.
Your options
There are three ways to give the CLI a key. Pick one per runner and do not mix them.
| Path | Command or variable | Best for |
|---|---|---|
| Browser login | sume login | A person at a laptop |
| Headless login | sume login --no-browser prints the approval URL | A remote terminal with a human |
| Key written to config | sume auth setup --api-key "$SUME_API_KEY" | CI and servers |
| Environment only | SUME_API_KEY, optional SUME_API_BASE_URL | Ephemeral containers |
A runner script
Local config is stored in ~/.sume-com/config.json by default. On an ephemeral runner that file disappears with the machine, which is what you want.
set -euo pipefail
: "${SUME_API_KEY:?SUME_API_KEY is not set}"
curl https://cli.sume.com/install -fsS | bash
export PATH="$HOME/.sume-com/bin:$PATH"
sume version
sume auth setup --api-key "$SUME_API_KEY"
sume auth statusAuth header mode
x-api-key is the current CLI default. If a proxy in your network only forwards Authorization, set SUME_API_AUTH_MODE=bearer. The API rejects a request that carries both headers with 401, so the CLI sends one.
Key hygiene
Use a key created for that pipeline from the API Keys dashboard, not a personal one, so you can revoke it alone. Never echo the key in a log; the :? guard above prints only the variable name. On a Windows runner the install line is irm https://cli.sume.com/install.ps1 | iex.
Sources
Related posts
More in Developers
- sume/auto for a former Sora feature: when to pin a model
Sume's sume/auto picks a family and never says which. Good for general clips, wrong when a brand needs one look. How to choose between auto and a pinned id.
- sume/auto for images: no model named, no seed, so pin ids for brand
sume/auto picks an image family and never says which, and there is no seed. When Auto is fine, and when to pin an id like GPT Image 2.5.
- Sume bulk items ignore on_active_run skip: allow is forced
Setting on_active_run skip or reject on a Sume bulk item does not stall the window, because the bulk controller runs every item with allow. What that changes.
- Count Sume bulk webhooks to know the queue is done, and the trap
A Sume bulk queue has no webhook, so some teams count per-item deliveries. Canceled and skipped runs never deliver, so a pure counter can hang. Use a hybrid.
Written by Sume