sume --agent --json: what it redacts before you paste output

Sume CLI --agent mode redacts or summarizes URL-like and account fields where supported. What to still strip before pasting output into a ticket or chat.

4 min readSume
All posts

Add --agent --json when a script or an assistant reads Sume CLI output: agent mode redacts or summarizes URL-like fields and account or workspace details where the CLI supports it. It is not a guarantee, so still check output before you paste it anywhere.

Everything here is from the Command reference, Agent skills and Security, read 2026-09-30.

Which commands take it?

The docs show it on job reads and on the readiness check.

Examples from the Command reference, read 2026-09-30
CommandPurpose
sume doctor --agent --jsonReadiness check
sume jobs status <job_id> --agent --jsonJob state
sume jobs events <job_id> --agent --jsonJob events
sume jobs result <job_id> --agent --jsonResult, only after completion

Why does the docs wording say where supported?

Both the commands page and the agent-skills page qualify the behavior with "where the CLI supports" it. So the flag reduces exposure, but it does not replace review. Job results can include first-party media URLs; the docs call them public URLs that are still user data.

What do I still strip before pasting?

Never print or commit SUME_API_KEY, the local ~/.sume-com/config.json or raw provider payloads. When reporting, use local filenames, redact query strings and private identifiers, and summarize media counts and types. A useful bug report has the command name, sanitized error code, request id and job id.

What should a bug report leave out?

API keys, signed URLs, full private media URLs, raw provider payloads, emails, and workspace or user ids, unless engineering explicitly asks. See Troubleshooting.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume