HeyGen API key permissions: /v3/api_keys/self vs Sume /v1/me
HeyGen's GET /v3/api_keys/self shows a key's name, scopes and expiry. On Sume, GET /v1/me verifies the key and returns non-secret account metadata.

To see what a HeyGen key can do, call GET /v3/api_keys/self: the September 2026 changelog says it returns the name, scope_mode, scopes and expiration of the key making the request. Sume's equivalent single call is GET /v1/me, which verifies the key and returns non-secret account and key metadata for the resolved workspace.
HeyGen facts are from its changelog; Sume facts are from Authentication and Public API, read 2026-09-30.
What does each endpoint tell me?
Both answer "is this key valid and what is it". The Sume docs describe the response only as non-secret account and key metadata, so do not build logic on scope fields the docs do not list.
| Question | HeyGen | Sume |
|---|---|---|
| Route | GET /v3/api_keys/self | GET /v1/me |
| Returned | Name, scope_mode, scopes, expiration | Non-secret account and key metadata, resolved workspace |
| Which keys | Works with any key | A developer API key |
How do I call /v1/me?
Send the key as a Bearer token or as x-api-key. Both are accepted, but send exactly one: a request carrying both is rejected with 401 unauthorized.
curl https://api.sume.com/v1/me \
-H "Authorization: Bearer $SUME_API_KEY"When should I run the check?
The rotation guidance is to create a replacement key, deploy it to your server, verify GET /v1/me, then revoke the old key from the dashboard. The same call works as a health step in a deploy script. More on key handling in Sume API keys, scopes and hosts.
Does Sume list scopes or expiry like HeyGen?
The docs quoted here do not say so for /v1/me. If you need expiry or scope detail, read the key's page in the dashboard or the OpenAPI schema for the response, rather than relying on this post.
Sources
Related posts
More in Developers
- HeyGen avatar voice id: default_voice_id vs Sume avatar_handle
HeyGen's PATCH /v3/avatars/{group_id} stores a default_voice_id. On Sume, TTS can take an avatar_handle and resolve that avatar's ready voice.
- HeyGen API idempotency key vs Sume: two different 409s
HeyGen returns 409 request_in_progress for an in-flight retry. Sume returns 409 idempotency_conflict only when a key is reused for a different payload.
- HeyGen Video Agent edit_plan vs Sume preview regenerate
HeyGen's edit_plan revises named scenes in one turn, up to 50 items. Sume has no in-place scene edit: regenerate preview stills, then render.
- HeyGen video scenes API vs Sume job result previews
HeyGen's GET /v3/videos/{video_id}/scenes returns each scene's visuals and script. Sume job results return media.sume.com artifacts and scene previews.
Written by Sume