Codex network policy now follows redirects: allow Sume's hosts
Codex 0.157.0 enforces network restrictions across redirects and cancels traffic when a policy change revokes access. Which Sume hosts to allow.

If Codex runs with a network policy, allow the three Sume hosts a video workflow touches: mcp.sume.com for the MCP server, api.sume.com for REST calls and media.sume.com for hosted results. Codex 0.157.0 enforces its network restrictions across redirects and ongoing HTTP and WebSocket traffic, and cancels traffic when a policy change revokes access.
The Codex behavior is from the changelog entry dated September 25, 2026, read 2026-10-01. The hosts are from Sume's docs.
What did 0.157.0 change?
Under Network Policy, the changelog says restrictions are now enforced across redirects and ongoing HTTP and WebSocket traffic, and that cancellation occurs when policy changes revoke access. A request that is allowed at the start can no longer slip to a disallowed host through a redirect, and a long transfer stops when you remove its host from the policy.
Which Sume hosts does a workflow use?
The hosted MCP endpoint is https://mcp.sume.com/mcp. REST generation endpoints live under https://api.sume.com/v1. Generated outputs are mirrored into Sume-owned media URLs, and the webhook payload example in the docs shows result URLs under https://media.sume.com/artifacts/.
| Host | Used for |
|---|---|
mcp.sume.com | Hosted MCP, OAuth authorize and consent |
api.sume.com | REST submits, status and results |
media.sume.com | Result files and uploads of source media |
What happens to my job if access is revoked mid-download?
Only the transfer stops. The job lives on Sume's side and the jobs page says a result is fetched once the job completes, so restore the host and fetch again with jobs_result or the result endpoint. Do not resubmit a paid request because a download was cancelled.
Do webhooks need an outbound allowance too?
No. A webhook is Sume calling your server, and it must be a public HTTPS URL; localhost and private-network URLs are rejected, per the webhooks docs. A Codex sandbox on your laptop is therefore not a webhook target. Poll with jobs_wait instead.
Sources
Related posts
More in Integrations
- Codex 0.158 approval review retry: what it means for a Sume call
Codex 0.158.0 retries an approval review when new user input arrives instead of aborting the pending action. Keep the Sume call's idempotency_key stable.
- Codex default_tools_approval_mode writes with Sume tools
With default_tools_approval_mode = "writes", Codex prompts for tools not marked read-only. Sume marks reads readOnlyHint true and writes false.
- CrewAI 1.15.22 traces human pauses: put the Sume dry run before them
CrewAI 1.15.22 collects human feedback and pause events in tracing. Place a Sume dry_run before the pause so the reviewer sees the cost they approve.
- Claude highlight edit from a long video: Resolve 21.1 vs Sume MCP
Resolve 21.1 lets Claude edit highlights inside Resolve. Sume's hosted MCP can do a cloud version: inspect, trim ranges, join with timeline_create.
Written by Sume