Sume schedule invoke command: check the host before you paste it

The curl command on a Sume schedule's trigger card uses api.dev.sume.com when you copy it from a *.dev.sume.com dashboard. Check the host before production.

3 min readSume
All posts

The trigger card on a schedule shows the invoke endpoint, the scopes and a copyable request. The Create a schedule page warns about one detail: the host depends on the dashboard you copied it from.

From docs.sume.com Create a schedule, read 2026-10-05
Dashboard hostInvoke host in the copied command
Any *.dev.sume.com hosthttps://api.dev.sume.com
All other dashboardshttps://api.sume.com

Why it bites

A key made for one environment does not belong in the other, and a schedule id from a development workspace does not exist in production. Pasting a dev command into production code gives a 404 or 403, depending on the key. Pasting a production key into a dev command sends a real credential to the wrong host. The docs say to examine the host before you paste a copied command into production code.

A habit that avoids it

Read the schedule's invoke_url from GET /v1/actions/{action_id} instead of copying shell text: the object carries it. Keep the base URL in one environment variable, and fail your deploy if it is not https://api.sume.com in production.

The command itself needs three things: the key, Content-Type: application/json and an Idempotency-Key, plus a body of {} when the schedule needs no input.

export SUME_API_BASE="https://api.sume.com"
case "$SUME_API_BASE" in
  *dev*) echo "dev host in production config" >&2; exit 1;;
esac
curl -sS -X POST "$SUME_API_BASE/v1/actions/$ACTION_ID/runs" \
  -H "Authorization: Bearer $SUME_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{}'

For the full list of errors the invoke path returns, see Advanced: run a schedule via API.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume