Codex network policy now follows redirects: allow Sume's hosts

Codex 0.157.0 enforces network restrictions across redirects and cancels traffic when a policy change revokes access. Which Sume hosts to allow.

4 min readSume
All posts

If Codex runs with a network policy, allow the three Sume hosts a video workflow touches: mcp.sume.com for the MCP server, api.sume.com for REST calls and media.sume.com for hosted results. Codex 0.157.0 enforces its network restrictions across redirects and ongoing HTTP and WebSocket traffic, and cancels traffic when a policy change revokes access.

The Codex behavior is from the changelog entry dated September 25, 2026, read 2026-10-01. The hosts are from Sume's docs.

What did 0.157.0 change?

Under Network Policy, the changelog says restrictions are now enforced across redirects and ongoing HTTP and WebSocket traffic, and that cancellation occurs when policy changes revoke access. A request that is allowed at the start can no longer slip to a disallowed host through a redirect, and a long transfer stops when you remove its host from the policy.

Which Sume hosts does a workflow use?

The hosted MCP endpoint is https://mcp.sume.com/mcp. REST generation endpoints live under https://api.sume.com/v1. Generated outputs are mirrored into Sume-owned media URLs, and the webhook payload example in the docs shows result URLs under https://media.sume.com/artifacts/.

Sume hosts to allow in a restricted Codex session, from the docs, read 2026-10-01.
HostUsed for
mcp.sume.comHosted MCP, OAuth authorize and consent
api.sume.comREST submits, status and results
media.sume.comResult files and uploads of source media

What happens to my job if access is revoked mid-download?

Only the transfer stops. The job lives on Sume's side and the jobs page says a result is fetched once the job completes, so restore the host and fetch again with jobs_result or the result endpoint. Do not resubmit a paid request because a download was cancelled.

Do webhooks need an outbound allowance too?

No. A webhook is Sume calling your server, and it must be a public HTTPS URL; localhost and private-network URLs are rejected, per the webhooks docs. A Codex sandbox on your laptop is therefore not a webhook target. Poll with jobs_wait instead.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume