Why Sume MCP results show [redacted]: the redaction field list
Sume MCP omits api_key fields and masks secrets and signed URLs as [redacted] in tool results. That is intended, not a failed call.

Seeing [redacted] in a Sume MCP tool result is intended. The server removes api_key, api_key_id and api_key_prefix entirely and replaces a list of sensitive keys with the string [redacted], so an agent transcript never carries a credential or a signed URL.
What gets masked
Redaction runs on tool results before they reach the model. Two behaviors exist: omission and masking. API key fields are omitted, so the key is not even present. A list of other fields is masked in place, and string URLs that look signed are masked wherever they appear.
| Rule | What the agent sees |
|---|---|
| api_key, api_key_id, api_key_prefix | field omitted |
| authorization, callback_url, headers, secret, signature, webhook_url | [redacted] |
| object_key, provider_payload, provider_result_url, provider_status_url, provider_task_id, raw_provider, source_url | [redacted] |
| url under webhook_delivery, upload or download | [redacted] |
| string URLs on R2 storage hosts or with signature, token or x-amz query parameters | [redacted] |
Why it is built this way
A transcript is stored, summarized and sometimes pasted into tickets. A signed upload URL or a webhook secret in it is a leak. Masking at the server means no client has to remember to scrub. It also explains the upload case: the signed upload.url from assets_upload_url comes back masked on the remote server, so a remote agent cannot PUT bytes with it. The upload URL post shows the working path with a public HTTPS source.
Detect it in code
If your harness must distinguish masked values, walk the result.
def redacted_paths(node, path=''):
out = []
if isinstance(node, dict):
for k, v in node.items():
out += redacted_paths(v, f'{path}.{k}' if path else k)
elif isinstance(node, list):
for i, v in enumerate(node):
out += redacted_paths(v, f'{path}[{i}]')
elif node == '[redacted]':
out.append(path)
return out
print(redacted_paths({'upload': {'url': '[redacted]'}}))Limits
Redaction hides values from the model, not from you: the same data is available through authorized REST calls, and your own logs may still hold what you sent. It also does not make a transcript safe by itself. Keep the system prompt free of keys, and do not echo private media URLs in reports.
How an agent should react
A model that sees [redacted] will sometimes try to retry the call, guess the value, or tell the user the call failed. None of that helps. The result is complete and the value was withheld on purpose. The agent.hint field points to the sanctioned alternative where one exists, such as mirroring an external image through a dedicated tool or using the REST bridge for sandbox-local bytes.
Checklist before you ship
- Never ask the model to reproduce a redacted value; it cannot.
- Use the REST bridge or the dashboard for flows that need a signed URL.
- Treat [redacted] in a result as expected, not as a failed call.
- Check the next_steps or hint field for the sanctioned alternative.
Sources
Related posts
More in Developers
- Windows PowerShell: install the Sume CLI, watch a 30 s render
Install the Sume CLI on Windows with one irm | iex line, set SUME_API_KEY, then use jobs watch and jobs download on a 30-second video job without resubmitting.
- X Ads API media upload: simple for images, chunked for all media
X's Ads API lists POST media/upload for images only and a chunked upload for all media. Use the chunked route for video you render with Sume.
- Grok Imagine video extension vs chaining clips on Sume
xAI extends a Grok Imagine clip from its final frame. Sume has no extend call for Grok: save the last frame and submit it as first_frame on the next job.
- xargs -P 3: send a prompt file to Wan 3.0 without losing quotes
A 17-line shell script fans a prompts.txt out to Sume /v1/videos with xargs -P 3. Six 2 s 480p Wan 3.0 jobs cost $0.75, and a rerun reuses each prompt's key.
Written by Sume