Sume SDK fetch wrapper: do not add an Authorization header
A fetch wrapper passed to createSumeClient must not add Authorization. Sending it with x-api-key returns 401, because Sume accepts only one credential.

If you wrap fetch for the Sume SDK, pass the request through untouched except for what you mean to change. The client sends x-api-key, and an extra Authorization header from your wrapper makes Sume answer 401 unauthorized with Send only one API key credential.
Sume facts are from the SDK overview and Authentication; the AI SDK point is from its 6.0.298 release notes. Read 2026-10-01.
Why would anything wrap fetch?
Instrumentation and frameworks do. The AI SDK 6.0.298 release says its default Node.js downloads stay protected by DNS validation and connection pinning even when frameworks or instrumentation wrap global fetch before or after the SDK loads. That is about its own downloads, not Sume calls, but it shows wrapped fetch is common. createSumeClient takes a fetch option for the same purpose, with retries and tracing as the use.
What goes wrong with two credentials?
The docs say sending both Authorization and x-api-key fails with 401 unauthorized, and there is no precedence rule: neither header wins. So a gateway token or session header added on top of the SDK's own breaks a request whose x-api-key was correct.
| Headers sent | Result |
|---|---|
x-api-key only (SDK default) | Accepted |
Authorization only | Accepted as a single credential |
| Both | 401 unauthorized: Send only one API key credential. |
What does a safe wrapper do?
Forward the arguments unchanged and observe the response. This one logs status and timing and touches no headers.
import { createSumeClient } from "@sume-com/sdk";
export const client = createSumeClient({
apiKey: process.env.SUME_API_KEY!,
fetch: async (...args: Parameters<typeof fetch>) => {
const started = Date.now();
const res = await fetch(...args);
console.log("sume", res.status, Date.now() - started, "ms");
return res;
},
});How do you debug a 401?
Check for a second credential first: an interceptor, a proxy, or an inherited header. Keep the request_id from the error envelope for support. See the API error fields post.
Sources
Related posts
More in Developers
- Sume SDK calls resolve with error: make your task throw
Generated Sume SDK operations return { data, error, response } and never throw. In Trigger.dev or Inngest, throw yourself or a failed run looks successful.
- Supabase Edge Function 400 s wall clock vs a Sume video job
Supabase Edge Functions cap wall clock at 150 s on Free and 400 s on Paid. Do not wait on a video: submit in one function and receive the webhook in another.
- Supabase Edge Function secrets: 100 per project, 2 for Sume
Supabase allows 100 secrets per project. A Sume webhook receiver needs two: your API key and the webhook signing secret. Names, rules and what to verify.
- sync-3 image formats JPEG PNG WebP vs Sume image URL rules
sync-3 accepts JPEG, PNG and WebP stills. Sume's docs set URL rules instead: a fetchable public HTTPS image, with private and signed URLs rejected.
Written by Sume