Why Sume MCP results show [redacted]: the redaction field list

Sume MCP omits api_key fields and masks secrets and signed URLs as [redacted] in tool results. That is intended, not a failed call.

4 min readSume
All posts

Seeing [redacted] in a Sume MCP tool result is intended. The server removes api_key, api_key_id and api_key_prefix entirely and replaces a list of sensitive keys with the string [redacted], so an agent transcript never carries a credential or a signed URL.

What gets masked

Redaction runs on tool results before they reach the model. Two behaviors exist: omission and masking. API key fields are omitted, so the key is not even present. A list of other fields is masked in place, and string URLs that look signed are masked wherever they appear.

Redaction rules on hosted Sume MCP results (read 2026-10-05 against the Sume codebase)
RuleWhat the agent sees
api_key, api_key_id, api_key_prefixfield omitted
authorization, callback_url, headers, secret, signature, webhook_url[redacted]
object_key, provider_payload, provider_result_url, provider_status_url, provider_task_id, raw_provider, source_url[redacted]
url under webhook_delivery, upload or download[redacted]
string URLs on R2 storage hosts or with signature, token or x-amz query parameters[redacted]

Why it is built this way

A transcript is stored, summarized and sometimes pasted into tickets. A signed upload URL or a webhook secret in it is a leak. Masking at the server means no client has to remember to scrub. It also explains the upload case: the signed upload.url from assets_upload_url comes back masked on the remote server, so a remote agent cannot PUT bytes with it. The upload URL post shows the working path with a public HTTPS source.

Detect it in code

If your harness must distinguish masked values, walk the result.

def redacted_paths(node, path=''):
    out = []
    if isinstance(node, dict):
        for k, v in node.items():
            out += redacted_paths(v, f'{path}.{k}' if path else k)
    elif isinstance(node, list):
        for i, v in enumerate(node):
            out += redacted_paths(v, f'{path}[{i}]')
    elif node == '[redacted]':
        out.append(path)
    return out

print(redacted_paths({'upload': {'url': '[redacted]'}}))

Limits

Redaction hides values from the model, not from you: the same data is available through authorized REST calls, and your own logs may still hold what you sent. It also does not make a transcript safe by itself. Keep the system prompt free of keys, and do not echo private media URLs in reports.

How an agent should react

A model that sees [redacted] will sometimes try to retry the call, guess the value, or tell the user the call failed. None of that helps. The result is complete and the value was withheld on purpose. The agent.hint field points to the sanctioned alternative where one exists, such as mirroring an external image through a dedicated tool or using the REST bridge for sandbox-local bytes.

Checklist before you ship

  • Never ask the model to reproduce a redacted value; it cannot.
  • Use the REST bridge or the dashboard for flows that need a signed URL.
  • Treat [redacted] in a result as expected, not as a failed call.
  • Check the next_steps or hint field for the sanctioned alternative.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume