TikTok url_ownership_unverified with a media.sume.com URL
PULL_FROM_URL needs a TikTok-verified domain or prefix, so a media.sume.com URL fails with 403. Upload the bytes with FILE_UPLOAD or host a copy on your domain.

url_ownership_unverified is a 403 returned when you start a TikTok post with source=PULL_FROM_URL and the URL is not on a domain or URL prefix you verified in the TikTok for Developers portal. A media.sume.com URL is on Sume's host, not a domain you control, so you cannot verify it and should not expect it to pass. Either download the file and send it with FILE_UPLOAD, or copy it to a domain you control and verify that.
TikTok's rules are from its media transfer guide and Direct Post reference; Sume's facts from Video generation and Structured output, read 2026-10-01.
What does TikTok require for PULL_FROM_URL?
The guide says the media URL must belong to a path you own, confirmed by adding a Domain or URL Prefix property to your app in the portal; you need manage or write access. The URL must use https and should not redirect. Redirects are not followed, and a 3xx response is treated as invalid.
How does domain versus prefix verification differ?
| Property | What counts as verified |
|---|---|
| Domain | All paths under that domain or its subdomains |
| Subdomain | static.example.com covers video.static.example.com, not example.com |
| URL prefix | Only URLs with the exact verified prefix |
| Prefix format | https:// + host + path + /; host must be a domain, not an IP |
Why can I not verify media.sume.com?
Sume serves generated files from media.sume.com, with a durable URL whose expires_at is null. That host is Sume's, so you cannot add its DNS record, and the URL is public by design: the docs note a durable URL is also a public URL. Sume's own tools run the other way too; Video Trim rejects a video_url that is not on the Sume media host with unsupported_media_source.
What are the two ways around it?
First, FILE_UPLOAD: poll the Sume job, download the video from the content URL, and send the bytes to the upload_url TikTok returns. Second, host a copy on your own verified domain and give TikTok that URL. Either way, keep your own copy rather than relying on a third party host. For chunking limits see TikTok chunk sizes.
Sources
Related posts
More in Developers
- TikTok photo post API: is_aigc label and auto_add_music
Set is_aigc to true on a TikTok photo post of generated images to add the AI-generated tag. auto_add_music is direct post only. And the audit rule.
- TikTok photo post title length: 90 runes, description 4000
TikTok's photo post API caps the title at 90 UTF-16 runes and the description at 4000, unlike video posts. How to count them and where Sume fits in.
- TikTok PULL_FROM_URL times out after one hour: keep the URL live
TikTok pulls a PULL_FROM_URL file at up to 100 Mbps and times out one hour after it starts. The URL must stay live; a Sume durable URL has no expiry.
- Concatenate audio files by API: parts, and no top-level url
Sume Timeline audio concat needs a parts array and refuses a top-level url or ranges. Each operation accepts its own keys; mixing them returns a stable code.
Written by Sume