Vercel Blob signed URL as a Sume image_url is rejected
Sume rejects signed or private URLs in input fields such as input.image_url. A Vercel Blob signed URL will fail; use a public-access store for Sume inputs.

Do not pass a Vercel Blob signed URL as a Sume input.image_url. Sume's docs say input URLs must be fetchable public HTTPS URLs and that signed or private URLs are rejected before generation submission. Put the file in a public-access Blob store and pass that URL.
Vercel facts are from its Blob page and changelog entries, read 2026-09-30. Sume facts are from Media inputs.
What is a Blob signed URL?
Per the Vercel changelog (2026-06-02), a signed URL is a scoped URL with an expiry: it covers a single operation (put, get, head, delete), a specific pathname, and a maximum expiry of 7 days, and needs @vercel/blob 2.4.0 or later. Private storage requires an authenticated token to read; public storage is readable by anyone with the URL.
What does Sume check?
Localhost, private-network URLs, non-HTTPS URLs, signed/private URLs and mismatched content types are rejected. The fields include input.image_url for Avatar 1.0 photos, scene.image_url, product_image, and video_url for face swap and captions. There is no separate asset upload step in the public contract, so the URL you pass is the input.
| Blob setup | URL type | Fit for Sume input |
|---|---|---|
| Public store | Link readable by anyone | Fits, if HTTPS and the content type matches |
| Private store | Needs a token | Rejected as private |
| Signed URL | Scoped and expiring | Rejected as signed |
Can I change a private store to public?
No. Vercel says the access mode cannot be changed after the store is created. Since 2026-09-23 you can create as many stores as you need, so create a separate public store for Sume inputs rather than loosening your private one. Only put files there that you are fine making public.
Is there another way to get a public URL?
Any host that serves the file over public HTTPS with the right content type works. See how to get a public URL for an image.
Sources
Related posts
More in Integrations
- Vercel Queues for Sume job webhooks: dedupe on job_id
Vercel Queues delivers at least once and bills keyed sends at 2x. To relay Sume webhooks through it, use job_id as the key and ack fast on the 10s limit.
- Zapier Catch Raw Hook: verify a Sume webhook signature
Zapier's Catch Raw Hook returns unparsed data plus headers, which a Sume HMAC check needs. Here is what to verify and the size limits to know.
- Zapier MCP on the Free plan, and Sume's own MCP endpoint
Zapier says MCP is now in its Free, Pro and Team plans. Sume's hosted MCP is a separate server at mcp.sume.com/mcp, reached with OAuth or an API key.
- Zed MCP OAuth scopes: what Sume asks for (mcp:read, mcp:write)
Zed 1.18.0 fixed OAuth for MCP servers with non-default scopes. Sume has two scopes, mcp:read (required) and mcp:write (opt-in on the consent page).
Written by Sume