Do API keys expire? Sume keys last until revoked
Some API keys expire and many last until revoked. Sume keys have no expiry date in current code, so rotation is on you. How and when to rotate.

Whether an API key expires depends on the provider: some keys carry an expiry date, and many keep working until someone revokes them. Sume API keys have no expiry date in current code. A key works until it is revoked, so deciding when to replace it is up to you.
The key behavior below comes from Authentication and API keys on docs.sume.com, read 2026-09-29. The points marked as current code were read from Sume's source the same day and can change.
What does a Sume key record keep track of?
In current code, a key record stores when it was created, when it was last used, and when it was revoked. It has no expiry field and no status that changes with time: a key is either active or revoked. The docs say API responses show key metadata such as id, name, prefix, scopes and last-used time, never the full secret.
| What is recorded | What it tells you |
|---|---|
| Created time | When the key was minted |
| Last-used time | Empty until first use; a key unused for months is a candidate to revoke |
| Revoked time | Empty while the key is active |
| Status | active or revoked |
| Expiry date | None: no such field exists |
What happens when a key is revoked?
A revoked key is refused with 401 unauthorized, the same status as a missing or malformed key. The fix the docs give is to check the header and create a new key if needed.
- Revocation is not instant everywhere: in current code the API caches key lookups for 15 seconds by default, so a revoked key can keep working for up to that long.
- In a team workspace, current code lets Admins revoke any team key; other members can revoke only the keys they created.
- Revoking your own credential only narrows access, so every role can do it.
Should API keys expire?
A key with no expiry is only as safe as your rotation habit. It stays valid through staff changes, old CI jobs and forgotten laptops unless someone revokes it. Since Sume keys don't lapse on their own, set your own triggers for replacing one:
- The key appeared in logs or chat history. The docs say to rotate it.
- The key was exposed. Rotate from the dashboard; Exposed API key? Revoke it, then check what it did walks through the cleanup.
- You need a scope the key lacks. Scopes are fixed when a key is created, and there is no API to add them later; an older key answers
403 insufficient_scope. - Someone who held the key left the project. Separate keys per person or service make this easier; see Can multiple people use the same API key?.
- The last-used time shows the key is idle. Revoke it.
How do I rotate a Sume API key without downtime?
Because an expired key is never the trigger, a planned rotation is overlap, not a cutover: create a replacement key, deploy it to your server, verify GET /v1/me (it returns the current API key, owner and workspace context, see API reference), then revoke the old key from the dashboard. How Sume API keys work covers the rotation steps and where to keep the key; Exposed API key? covers the emergency version.
Put the replacement date in your own calendar or secret manager at creation time. The key record has no date field that could prompt it for you.
Do API keys change on their own?
No. A Sume key doesn't rotate or regenerate by itself. A different secret, or different scopes, means creating a new key and revoking the old one. The dashboard reveals the full secret only when a key is created, so a lost secret also means a new key.
Sources
Related posts
More in Developers
- fal.ai API rate limit: concurrency from 2 up to 40
fal.ai limits how many requests run at once, not requests per minute: 2 for a new account, rising with credit purchases to 40 self-serve.
- fal AI FFmpeg API: endpoints, inputs and prices
fal hosts FFmpeg as model endpoints: merge videos, merge audio and video, extract a frame, compose tracks. Called with a fal key, priced per second.
- FFmpeg: add a watermark image to a video with overlay
Add a watermark image to a video with FFmpeg: pass the logo as a second input and use overlay=W-w-10:H-h-10 for the bottom-right corner.
- FFmpeg burn subtitles into video: subtitles filter, force_style
Burn subtitles into a video with FFmpeg's subtitles filter: -vf subtitles=subs.srt re-encodes the picture, and force_style overrides the font and colour.
Written by Sume