Airtable has no webhook signature check: verify Sume first
Airtable's When webhook received trigger cannot verify signatures and caps payloads at 100kb. Verify the Sume signature in a relay and forward a small object.

Put a small relay between Sume and Airtable: verify the sume-v1 signature there, then forward a compact JSON object to the Airtable webhook URL. Airtable's page says it does not support signature verification for webhooks, so a Sume delivery sent straight to it cannot be authenticated by Airtable.
Sume facts are from the Verifying webhooks docs; the Airtable limits were read 2026-09-30.
What does the Airtable trigger accept?
Airtable lists a payload limit of 100kb per request, five requests per second, POST only, and a JSON body with an object at the top level.
| Topic | Airtable trigger | Sume delivery |
|---|---|---|
| Signature | Not verified | sume-v1 HMAC-SHA256 header |
| Payload size | 100kb | payload: null above 1 MiB |
| Rate | 5 requests per second | Up to 10 attempts on failure |
What does the relay do?
It refuses an empty secret, verifies the raw body, and forwards only what the automation needs. Fetch the full result from result_url later instead of copying a large payload.
import { verifyWebhook } from "@sume-com/sdk";
export default {
async fetch(request: Request, env: Record<string, string>) {
const secret = env.SUME_COM_WEBHOOK_SIGNING_SECRET;
if (!secret || !env.AIRTABLE_HOOK_URL) {
return new Response("not configured", { status: 500 });
}
const body = await request.text();
const ok = await verifyWebhook({ body, headers: request.headers, secret });
if (!ok) return new Response("bad signature", { status: 401 });
const event = JSON.parse(body);
const slim = { event: event.event, request_id: event.request_id };
const res = await fetch(env.AIRTABLE_HOOK_URL, {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify(slim),
});
return new Response(null, { status: res.ok ? 204 : 502 });
},
};Why return 502 on a failed forward?
A non-2xx makes Sume retry, up to 10 attempts. A 204 after a failed forward would silently drop the event.
What about the five-per-second cap?
A busy bulk queue can finish several items close together. Airtable does not say what it does past the cap, so keep a poll of the queue as a backup and dedupe on request_id.
Sources
Related posts
More in Developers
- AI Act Article 50 in force: what to log per generated file
Article 50 applies from 2 August 2026. Keep a per-file record of job id, request id and artifact URL from Sume, and know what the docs leave unsaid on marking.
- Why Sume Agent Completions rejects assistant messages
An assistant turn in messages[] returns 400 invalid_request on Sume Agent Completions. Only system and user turns work; each call runs in a fresh thread.
- Keep the source's channels and sample rate when extracting audio
Adobe lists Match Source audio channels and sample rate in Premiere 26.5. Sume audio-detach keeps both by default: channels source, sample_rate omitted, wav.
- Extract audio from a long video: the 900 s output cap and range
Audio detach takes sources up to 1800 s but outputs at most 900 s. For a longer track pass range and detach in two calls. Errors included.
Written by Sume