xAI file URLs auto-expire; Sume fetches image_url once at create

xAI's Files API can serve public URLs that auto-expire. Sume fetches an attachment image_url at run creation and copies it. What that means for hosting.

5 min readSume
All posts

If your batch needs product images reachable by URL, how long must they stay up? It depends on who fetches them and when. The xAI release notes (read 2026-10-04) describe a Files API option for public URLs with auto-expiry, with the range given as 1 hour to 30 days. On Sume the answer is shorter: the Format API docs say Sume fetches every attachment when you create the run, checks its real type and size, and copies it into durable storage.

So an image only has to be reachable at the moment of the create call, not while the run renders. That changes how you host source images for a holiday batch.

What Sume checks at create time

Each attachments entry is { "type": "input_image", "image_url": ... } with a public HTTPS URL, reachable without authentication. A run takes up to 30 images. If the fetch fails, the create fails with an error you can act on, such as attachment_fetch_failed (502) for an unreachable host, hotlink protection or a non-2xx answer, with details.index naming the attachment. For a bulk queue the same errors fire before the queue exists, so nothing is dispatched.

A true idempotent replay does not re-fetch your images, so a retry after a crash will not fail because a short-lived URL has since expired.

The usual reasons a fetch fails

The Sume docs name the cases: an unreachable host, hotlink protection, or a non-2xx answer, reported as attachment_fetch_failed with details.index. Related errors are invalid_attachment, attachment_not_found and attachment_too_large, all fired while resolving attachments before any queue exists.

Hotlink protection is the one that surprises people, because the image loads in a browser from your own site. Serve source images from a bucket or CDN path that does not check the referer, and test with a plain request that has no cookies. Signed URLs work if they remain valid for the few seconds the create call takes; they do not need to last for the run.

Hosting plan for a batch

When a source URL must be live, xAI release notes and Sume docs read 2026-10-04
xAI public file URLSume attachment image_url
Who fetchesWhatever you give the URL toSume, at create time
Needed after thatUntil the auto-expiry you choseNot needed; Sume keeps a durable copy
ExpiryAuto-expiry, 1 hour to 30 days per the notesNot applicable to your URL
Failure modeLink dead when used late4xx or 5xx on create, with details.index

Pre-flight every URL

Check the URLs from your own server before posting a queue of 100. This script validates scheme and shape for a list and reports the index of each bad entry, mirroring how Sume names a bad attachment. It does not fetch anything, so it runs offline.

from urllib.parse import urlparse

urls = [
    "https://cdn.example.com/p/mug-01.jpg",
    "http://cdn.example.com/p/mug-02.jpg",
    "https://cdn.example.com",
    "https://cdn.example.com/p/mug-04.png",
]
bad = []
for i, u in enumerate(urls):
    p = urlparse(u)
    if p.scheme != "https" or not p.netloc or p.path in ("", "/"):
        bad.append(i)
print("bad indexes:", bad)
assert bad == [1, 2]

Keep the real fetch test too

A shape check cannot see hotlink protection or a private bucket. Fetch a sample of each distinct host with a plain GET and no cookies before the run, because that is the condition Sume's fetch meets. Fix the host, not the item, when a whole domain fails.

Sources

Related posts

More in Comparisons

All Comparisons posts

Written by Sume