Team API keys: which wallet does a Sume run charge?

A Sume run charges the workspace its API key belongs to. A team key spends the team wallet; a personal key on a team Format is refused with 403.

5 min readSume
All posts

A Sume run charges the workspace that its API key belongs to. A team key spends the team's wallet and counts against the team's generation concurrency; a personal key spends from the workspace it belongs to. That is why a personal key held by a team member is refused on a team Format, with 403 workspace_key_required.

This comes from Authentication, Create a Format run and Format API errors, read 2026-09-29. The changelog also notes an org / team pooled wallet in v0.2.59; the pages checked say no more than that.

How does a key decide who pays?

API keys are workspace-scoped, and Sume resolves the workspace, owner and key metadata from the key itself. You never send a workspace_id in a request body. Balance and usage reads are scoped to the key's workspace too, so GET /v1/balance shows the wallet that key would spend.

Format runs make the rule explicit: runs spend from the workspace the key belongs to. There is no workspace field on the request, so the key is the actor.

What changes for a team Format?

The docs give the reason for the team-key rule: it follows the money. A team Format's runs bill the team wallet, count against the team's generation concurrency, and read their media back through the team workspace. A personal key would split those. Create the key from the team's dashboard; personal keys stay right for personal Formats.

From Create a Format run and Format API errors, read 2026-09-29.
SituationWhat happens
Team Format, team keyThe run bills the team wallet and uses the team's concurrency
Team Format, personal key of a member403 workspace_key_required; details.workspace_id names the workspace to mint a key in
Team wallet not funded402 organization_wallet_not_provisioned; an admin has to fund it; nothing ran
Wallet cannot cover the run402 insufficient_credits with next_action: add_funds

What if another workspace shared the Format with me?

You call the Format at the owner's address with your own team key. The run, its spend, its concurrency slot and its media are your workspace's, not the owner's. Each workspace keeps its own run history and its own bill, and a key from one never reads the other's runs. The owner still decides whether the Format takes API calls at all. For the grant flow, see sharing a Format.

How do I confirm which workspace a key belongs to?

Call GET /v1/me. The docs describe it as verifying the key and returning the resolved workspace context, and the reference shows workspace_id and the key's id, name, prefix and scopes. Then read the balance for that key.

curl -sS https://api.sume.com/v1/me \
  -H "Authorization: Bearer $SUME_API_KEY"

curl -sS https://api.sume.com/v1/balance \
  -H "Authorization: Bearer $SUME_API_KEY"

What do the docs not say?

They do not describe how a pooled team wallet is funded, split between members or capped per member. The changelog line and the two 402 codes are the extent of it. Top-ups themselves are dashboard operations; the public API has balance and usage reads and no top-up call. For anything about seats or per-member budgets, ask Sume before you rely on it.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume