Black Friday webhooks: staging and production URLs for a Sume Format

Webhook URLs must be public HTTPS and are re-checked at delivery. Use a separate URL per environment and send a test delivery before a bulk queue goes out.

3 min readSume
All posts

Sume only delivers to a public HTTPS URL, so a laptop localhost address is not a staging endpoint. Give staging and production each a real hostname and pass the right one per run in communication.webhook_url.

The delivery rules

  • Public HTTPS, at most 2048 characters.
  • The URL is re-validated at delivery time, not only at submit.
  • A 3xx is not followed and counts as a failed attempt, so do not put a redirect in front of your handler.
  • Ten attempts, 10 seconds each, with backoff that doubles from 30 seconds and caps at one hour; Retry-After is honored.

One URL per environment

Read the URL from config, never from a literal. The test endpoint sends a webhook.test payload so you can see a signed delivery before real runs exist.

curl -sS -X POST "https://api.sume.com/v1/webhooks/test-deliveries" \
  -H "Authorization: Bearer $SUME_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "webhook_url": "'"$STAGING_WEBHOOK_URL"'" }'

Verify, do not trust

Signatures are HMAC-SHA256 over <timestamp>.<raw_body> in the x-sume-webhook-signature: sume-v1=<hex> header, with a 300 second tolerance. Verify against the raw body and refuse an empty secret. The secret name used in the docs is SUME_COM_WEBHOOK_SIGNING_SECRET, and x-sume-webhook-secret-fingerprint tells you which secret signed it, which helps if staging and production use different ones.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume