sume --agent --json: what it redacts before you paste output
Sume CLI --agent mode redacts or summarizes URL-like and account fields where supported. What to still strip before pasting output into a ticket or chat.

Add --agent --json when a script or an assistant reads Sume CLI output: agent mode redacts or summarizes URL-like fields and account or workspace details where the CLI supports it. It is not a guarantee, so still check output before you paste it anywhere.
Everything here is from the Command reference, Agent skills and Security, read 2026-09-30.
Which commands take it?
The docs show it on job reads and on the readiness check.
| Command | Purpose |
|---|---|
| sume doctor --agent --json | Readiness check |
| sume jobs status <job_id> --agent --json | Job state |
| sume jobs events <job_id> --agent --json | Job events |
| sume jobs result <job_id> --agent --json | Result, only after completion |
Why does the docs wording say where supported?
Both the commands page and the agent-skills page qualify the behavior with "where the CLI supports" it. So the flag reduces exposure, but it does not replace review. Job results can include first-party media URLs; the docs call them public URLs that are still user data.
What do I still strip before pasting?
Never print or commit SUME_API_KEY, the local ~/.sume-com/config.json or raw provider payloads. When reporting, use local filenames, redact query strings and private identifiers, and summarize media counts and types. A useful bug report has the command name, sanitized error code, request id and job id.
What should a bug report leave out?
API keys, signed URLs, full private media URLs, raw provider payloads, emails, and workspace or user ids, unless engineering explicitly asks. See Troubleshooting.
Sources
Related posts
More in Developers
- Asset id or public HTTPS URL? What Sume inputs accept
Sume generation fields take public HTTPS URLs directly. Localhost, private, non-HTTPS, signed URLs and wrong content types are rejected. When an asset id helps.
- Sume assets from the terminal: upload-url, complete, download
The Sume CLI registers an asset in three write-gated steps and reads it back with download-url or download. Flags, the confirm gate and what stays private.
- sume/auto video defaults: 720p, 8 seconds, 3 to 10 s at 16:9 or 9:16
Leave resolution and duration off a sume/auto video request and Sume uses 720p and 8 seconds. The Auto envelope is 3 to 10 seconds at 16:9 or 9:16.
- Install the Sume CLI in CI: checksums and pinned release tags
The hosted installer verifies checksums.txt and will not overwrite another sume on PATH. To pin, swap latest for a release tag such as v0.1.6.
Written by Sume