Airtable has no webhook signature check: verify Sume first

Airtable's When webhook received trigger cannot verify signatures and caps payloads at 100kb. Verify the Sume signature in a relay and forward a small object.

4 min readSume
All posts

Put a small relay between Sume and Airtable: verify the sume-v1 signature there, then forward a compact JSON object to the Airtable webhook URL. Airtable's page says it does not support signature verification for webhooks, so a Sume delivery sent straight to it cannot be authenticated by Airtable.

Sume facts are from the Verifying webhooks docs; the Airtable limits were read 2026-09-30.

What does the Airtable trigger accept?

Airtable lists a payload limit of 100kb per request, five requests per second, POST only, and a JSON body with an object at the top level.

Trigger limits against Sume behavior, read 2026-09-30. Sume: Run webhooks.
TopicAirtable triggerSume delivery
SignatureNot verifiedsume-v1 HMAC-SHA256 header
Payload size100kbpayload: null above 1 MiB
Rate5 requests per secondUp to 10 attempts on failure

What does the relay do?

It refuses an empty secret, verifies the raw body, and forwards only what the automation needs. Fetch the full result from result_url later instead of copying a large payload.

import { verifyWebhook } from "@sume-com/sdk";

export default {
  async fetch(request: Request, env: Record<string, string>) {
    const secret = env.SUME_COM_WEBHOOK_SIGNING_SECRET;
    if (!secret || !env.AIRTABLE_HOOK_URL) {
      return new Response("not configured", { status: 500 });
    }
    const body = await request.text();
    const ok = await verifyWebhook({ body, headers: request.headers, secret });
    if (!ok) return new Response("bad signature", { status: 401 });

    const event = JSON.parse(body);
    const slim = { event: event.event, request_id: event.request_id };
    const res = await fetch(env.AIRTABLE_HOOK_URL, {
      method: "POST",
      headers: { "content-type": "application/json" },
      body: JSON.stringify(slim),
    });
    return new Response(null, { status: res.ok ? 204 : 502 });
  },
};

Why return 502 on a failed forward?

A non-2xx makes Sume retry, up to 10 attempts. A 204 after a failed forward would silently drop the event.

What about the five-per-second cap?

A busy bulk queue can finish several items close together. Airtable does not say what it does past the cap, so keep a poll of the queue as a backup and dedupe on request_id.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume