Vidu 'Authorization: Token' vs Sume 'Bearer': one HTTP client
Vidu wants 'Authorization: Token <key>'; Alibaba Model Studio and Sume want 'Bearer <key>'. A small header helper for a ported client.

Vidu's Q4 Preview page asks for Authorization: Token <key>. Alibaba's Wan 3.0 page and Sume both use Authorization: Bearer <key>. If you port a Vidu client to Sume and keep the word Token, every call fails before it reaches a model, so make the scheme a per-vendor setting instead of a string buried in the code.
Which scheme does each service use?
All three are plain HTTP headers on a JSON POST. Only the word in front of the key changes.
| Service | Header | Where it was read |
|---|---|---|
| Vidu Q4 Preview | Authorization: Token <key> | Vidu image-to-video page |
| Alibaba Model Studio, Wan 3.0 | Authorization: Bearer <key> | Alibaba Wan3.0 API reference |
| Sume /v1/videos | Authorization: Bearer $SUME_API_KEY | Sume video generation docs |
How do you keep the scheme out of the call sites?
Put the scheme next to the base URL in one place. The helper below also refuses an empty key, which is the usual cause of a confusing 401 in a script that read an unset environment variable.
import os
SCHEMES = {"vidu": "Token", "alibaba": "Bearer", "sume": "Bearer"}
def headers(vendor: str, key: str | None) -> dict:
if not key:
raise ValueError(f"no API key set for {vendor}")
return {
"Authorization": f"{SCHEMES[vendor]} {key}",
"Content-Type": "application/json",
}
print(headers("vidu", "k1"))
print(headers("sume", os.environ.get("SUME_API_KEY", "demo")))What else changes besides the header?
Three other things change in the same port.
- The host: Vidu and Alibaba have their own hosts; Sume is
https://api.sume.com/v1/videos. - The key: one Sume API key covers every listed video model, so there is no second vendor account to open.
- The model id: Vidu's
viduq4-previewis not in the Sume catalog (read 2026-10-09); use an id fromGET /v1/videos/models.
Where do you get the Sume key?
Create it in the dashboard and send it as a Bearer token on every request, as in the video generation docs. Treat it like a password and load it from the environment, never from the repository.
Sources
Related posts
More in Developers
- Vidu is_rec and Wan prompt_extend: prompt rewrite vs Sume
Vidu's is_rec and Alibaba's prompt_extend can rewrite your prompt. Sume's documented video fields have no such switch. How to drop them and compare results.
- Vidu's payload pass-through vs Sume: where to keep your order id
Vidu lets you send a payload string that comes back untouched. Sume's video request has no such field; use an Idempotency-Key and your own job table instead.
- Vidu Q4 base64 images and a 20 MB body vs Sume's HTTPS URLs
Vidu accepts base64 images with a 20 MB request body cap. Sume wants a public HTTPS URL. Base64 math, and a small check before you submit.
- Vidu Q4 callback_url receiver, moved to Sume's signed webhooks
Vidu and Sume both POST a callback. Sume's needs HTTPS, fires on terminal events only and signs the raw body with HMAC. What to change in the receiver.
Written by Sume