Authenticate the Sume CLI on a CI runner without a browser login

On CI, skip sume login: install the CLI, run sume auth setup with an API key from a secret, and confirm with sume auth status before any job step.

5 min readSume
All posts

Run sume auth setup --api-key "$SUME_API_KEY" with the key injected from your CI secret store, then sume auth status. The browser flow is the recommended path for people; the docs say manual API-key setup and environment variables are still supported for CI and server automation.

Your options

There are three ways to give the CLI a key. Pick one per runner and do not mix them.

CLI authentication paths (read 2026-10-04)
PathCommand or variableBest for
Browser loginsume loginA person at a laptop
Headless loginsume login --no-browser prints the approval URLA remote terminal with a human
Key written to configsume auth setup --api-key "$SUME_API_KEY"CI and servers
Environment onlySUME_API_KEY, optional SUME_API_BASE_URLEphemeral containers

A runner script

Local config is stored in ~/.sume-com/config.json by default. On an ephemeral runner that file disappears with the machine, which is what you want.

set -euo pipefail
: "${SUME_API_KEY:?SUME_API_KEY is not set}"

curl https://cli.sume.com/install -fsS | bash
export PATH="$HOME/.sume-com/bin:$PATH"

sume version
sume auth setup --api-key "$SUME_API_KEY"
sume auth status

Auth header mode

x-api-key is the current CLI default. If a proxy in your network only forwards Authorization, set SUME_API_AUTH_MODE=bearer. The API rejects a request that carries both headers with 401, so the CLI sends one.

Key hygiene

Use a key created for that pipeline from the API Keys dashboard, not a personal one, so you can revoke it alone. Never echo the key in a log; the :? guard above prints only the variable name. On a Windows runner the install line is irm https://cli.sume.com/install.ps1 | iex.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume