Sume assets from the terminal: upload-url, complete, download

The Sume CLI registers an asset in three write-gated steps and reads it back with download-url or download. Flags, the confirm gate and what stays private.

4 min readSume
All posts

Register an asset with sume assets upload-url, upload the bytes to the URL it gives you, then confirm with sume assets complete <asset_id>. Each write needs --confirm-submit. Read it back with sume assets download-url <asset_id> or sume assets download <asset_id> --output-dir ./assets.

Everything here is from the Command reference and Jobs and media inputs, read 2026-09-30.

What are the asset commands?

Reads are free of a gate; registering and uploading are write-gated.

Asset commands from the Command reference, read 2026-09-30
CommandGateUse
sume assets list / get <asset_id>NoneInspect assets
sume assets create --source-url <https url>--confirm-submitRegister from a public URL
sume assets upload-url --content-type --size-bytes--confirm-submitGet an upload target
sume assets complete <asset_id>--confirm-submitFinish an upload
sume assets download-url / downloadNoneRead back

What does the upload sequence look like?

The hosted MCP page describes the same shape: create an upload URL, the client PUTs the bytes, then complete. Inspect exact flags with sume tools schema assets.create --json and the related schemas.

sume assets upload-url --content-type image/png --size-bytes 12345 --confirm-submit
# upload the file bytes to the URL returned above
sume assets complete <asset_id> --confirm-submit
sume assets download <asset_id> --output-dir ./assets

Do I need an asset at all?

Often not. The docs say to prefer public HTTPS media URLs in generation payloads when you do not need first-party asset ids or the asset lifecycle.

What should I keep private?

Treat signed upload and download URLs as temporary secrets: they are not part of the launch public API contract. When reporting, use local filenames, redact query strings, and never paste SUME_API_KEY or ~/.sume-com/config.json. See Security.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume