Vercel Sandbox static egress IP: do I need to allowlist Sume?

Secure Compute gives Vercel Sandbox static egress IPs. Calling Sume needs only an API key over HTTPS; for webhooks into your app, verify the signature.

4 min readSume
All posts

No allowlist is needed to call Sume from a Vercel Sandbox. Sume's API takes a key over public HTTPS. For webhooks coming back, I found no published Sume source-IP list in the webhook docs I read, so verify the HMAC signature rather than building an IP rule.

What Vercel shipped

On September 30 Vercel said sandboxes can attach to Secure Compute networks. Public internet traffic leaves through static IPs on the dedicated network, private AWS VPC resources are reachable through VPC peering, and you attach a network by passing a network ID at creation or calling sandbox.update(), which takes effect on the next session. It is limited to Enterprise teams that have Secure Compute enabled.

Which direction needs which control

Sandbox networking versus Sume traffic (read 2026-10-06)
TrafficIP-based controlWhat Sume offers instead
Sandbox calls api.sume.comStatic egress IP, only useful if the destination filters by IPAuthentication with exactly one of Authorization: Bearer or x-api-key; sending both fails with 401
Sume calls your receiverNone documented from SumeSigned POST; x-sume-webhook-signature, timestamp header for a replay window you set, job_id for dedupe
Your receiver lives in a VPCVPC peering reaches the sandbox, not SumePublic HTTPS URL required; private-network URLs are rejected

The receiver rule that follows

A webhook receiver behind Secure Compute still has to be reachable from the public internet, because Sume rejects private-network webhook URLs. Put a thin public endpoint in front, verify the signature, record the event, and return a 2xx quickly; the docs list a 10-second timeout per attempt. Then hand the work to the private side. If the endpoint is down, Sume retries up to ten times, and the job itself stays completed; read it from the job result endpoint.

Also remember that Secure Compute is Enterprise-only. A team without it still calls Sume the same way, with the same key and the same caps.

Where static IPs do help

If your own vendors insist on IP filtering, the sandbox's static egress covers those calls. For anything touching Sume, key hygiene matters more: one credential header, and key scopes such as agent_completions:write.

One detail worth checking in your own setup: changes made with sandbox.update() apply on the next session, not the running one. If you attach a network to an existing sandbox mid-job, in-flight calls to Sume still leave from the old address. That does not break calls to Sume, since the docs describe key authentication and no IP filter, but it matters if you later add an IP filter in front of your own receiver.

Sources

More in Integrations

All Integrations posts

Written by Sume