Sume SDK fetch wrapper: do not add an Authorization header

A fetch wrapper passed to createSumeClient must not add Authorization. Sending it with x-api-key returns 401, because Sume accepts only one credential.

4 min readSume
All posts

If you wrap fetch for the Sume SDK, pass the request through untouched except for what you mean to change. The client sends x-api-key, and an extra Authorization header from your wrapper makes Sume answer 401 unauthorized with Send only one API key credential.

Sume facts are from the SDK overview and Authentication; the AI SDK point is from its 6.0.298 release notes. Read 2026-10-01.

Why would anything wrap fetch?

Instrumentation and frameworks do. The AI SDK 6.0.298 release says its default Node.js downloads stay protected by DNS validation and connection pinning even when frameworks or instrumentation wrap global fetch before or after the SDK loads. That is about its own downloads, not Sume calls, but it shows wrapped fetch is common. createSumeClient takes a fetch option for the same purpose, with retries and tracing as the use.

What goes wrong with two credentials?

The docs say sending both Authorization and x-api-key fails with 401 unauthorized, and there is no precedence rule: neither header wins. So a gateway token or session header added on top of the SDK's own breaks a request whose x-api-key was correct.

Credential headers and result, from the Sume docs read 2026-10-01
Headers sentResult
x-api-key only (SDK default)Accepted
Authorization onlyAccepted as a single credential
Both401 unauthorized: Send only one API key credential.

What does a safe wrapper do?

Forward the arguments unchanged and observe the response. This one logs status and timing and touches no headers.

import { createSumeClient } from "@sume-com/sdk";

export const client = createSumeClient({
  apiKey: process.env.SUME_API_KEY!,
  fetch: async (...args: Parameters<typeof fetch>) => {
    const started = Date.now();
    const res = await fetch(...args);
    console.log("sume", res.status, Date.now() - started, "ms");
    return res;
  },
});

How do you debug a 401?

Check for a second credential first: an interceptor, a proxy, or an inherited header. Keep the request_id from the error envelope for support. See the API error fields post.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume