What an agent should log when it calls Sume: ids yes, signed URLs no

Safe log fields for agents using the Sume API, CLI and MCP: request ids, job ids, status, sanitized media metadata. Never keys, signed URLs or transcripts.

3 min readSume
All posts

An agent that calls Sume should log request ids, job ids when necessary, high-level status and sanitized media metadata, and should never log API keys, signed URLs, raw private media URLs or large amounts of user content and transcripts (Safe automation).

Log or drop

Based on the safe-automation page
FieldLog it?
request_idYes
job idYes, when needed to follow up
status such as queued, processing, completedYes
media metadata (sanitized: type, duration, size)Yes; the page says "sanitized media metadata"
API key or OAuth tokenNever
signed or private media URLNever
full transcript or user prompt textNo; the page lists too much user content or too many transcripts as unsafe

A redacting helper

A small filter in Python that keeps the safe keys from a response and drops the rest.

SAFE_KEYS = {"id", "request_id", "status", "job_status", "resource_status", "video_url"}

def loggable(resp: dict) -> dict:
    return {k: v for k, v in resp.items() if k in SAFE_KEYS}

print(loggable({"id": "job_123", "status": "completed", "authorization": "Bearer secret"}))

Boundaries that matter more than logs

The API key or app session selects the workspace; tools must not accept a workspace id from the user. Spending actions should be explicit: on hosted MCP use OAuth mcp:read for exploration, and grant mcp:write or use an API key before paid tools such as generate_image or avatars_create. Paid and write calls must send idempotency_key.

Sources

Related posts

More in Agents

All Agents posts

Written by Sume