What an agent should log when it calls Sume: ids yes, signed URLs no
Safe log fields for agents using the Sume API, CLI and MCP: request ids, job ids, status, sanitized media metadata. Never keys, signed URLs or transcripts.

An agent that calls Sume should log request ids, job ids when necessary, high-level status and sanitized media metadata, and should never log API keys, signed URLs, raw private media URLs or large amounts of user content and transcripts (Safe automation).
Log or drop
| Field | Log it? |
|---|---|
| request_id | Yes |
| job id | Yes, when needed to follow up |
| status such as queued, processing, completed | Yes |
| media metadata (sanitized: type, duration, size) | Yes; the page says "sanitized media metadata" |
| API key or OAuth token | Never |
| signed or private media URL | Never |
| full transcript or user prompt text | No; the page lists too much user content or too many transcripts as unsafe |
A redacting helper
A small filter in Python that keeps the safe keys from a response and drops the rest.
SAFE_KEYS = {"id", "request_id", "status", "job_status", "resource_status", "video_url"}
def loggable(resp: dict) -> dict:
return {k: v for k, v in resp.items() if k in SAFE_KEYS}
print(loggable({"id": "job_123", "status": "completed", "authorization": "Bearer secret"}))Boundaries that matter more than logs
The API key or app session selects the workspace; tools must not accept a workspace id from the user. Spending actions should be explicit: on hosted MCP use OAuth mcp:read for exploration, and grant mcp:write or use an API key before paid tools such as generate_image or avatars_create. Paid and write calls must send idempotency_key.
Sources
Related posts
More in Agents
- Run the Sume video agent from your backend with Agent Completions
POST /v1/agent/completions runs the same agent as the Sume Agents chat, with tools and media generation, and returns an async run receipt you poll or webhook.
- Scheduled AI video agent runs: cron, API triggers, and receipts
A Sume schedule is a saved Agents automation that runs on a cron cadence and returns a run receipt. Author it in the dashboard; start and monitor runs by API.
- What is a video agent? How Sume defines and runs one
In Sume's docs, a video agent is a sandbox Agent that composes generation tools into a post-ready video. Brief it in chat, or call it over HTTP.
- Sume Agent Completions vs Format vs Scheduled runs: request body diff
Sume Format runs, Scheduled runs, and Agent Completions share field names, not rules: spend-cap defaults, null, on_active_run, attachments, and scopes differ.
Written by Sume