callback_url for 30-second Seedance 2.5 and Wan 3.0 jobs
Add callback_url (HTTPS) to a 30-second seedance-2.5 or wan-3.0 job and Sume POSTs a signed webhook when it finishes. Headers and what to verify.

Add callback_url (it must be HTTPS) to the request and Sume POSTs to it when the job reaches a terminal state. The body is signed, with x-sume-webhook-timestamp and x-sume-webhook-signature headers, so verify before you trust it.
A 30-second render is the case where polling every 30 seconds adds up; a webhook replaces the loop.
Request
curl -X POST https://api.sume.com/v1/videos \
-H "Authorization: Bearer $SUME_API_KEY" \
-H "Content-Type: application/json" \
-d '{"model": "wan-3.0", "prompt": "Drone shot over a harbor at dawn",
"duration": 30, "resolution": "480p",
"callback_url": "https://example.com/hooks/sume"}'What to handle
| Step | Detail |
|---|---|
| Signature | verify the raw JSON body with the signing secret; refuse if the secret is empty |
| Timestamp | check the timestamp header to reject replays |
| Envelope | Sume's standard job webhook, not OpenRouter's video.generation.* |
| Fallback | poll the polling_url if no callback arrives |
Notes
The webhook guide and the exact verification steps are in the API reference. Use the job status endpoint to double check any job you did not hear about.
Security basics
A webhook endpoint is public, so it needs verification. Compute the signature over the raw body, compare it in constant time, and reject requests with an old timestamp. Your verifier must refuse to run with an empty secret.
Respond quickly with a 2xx and do the heavy work (download, transcode) in a queue.
Webhook or poll
Use a webhook for production pipelines and polling for scripts and notebooks. Doing both is safe: the webhook triggers the next step and a slow poll catches anything missed.
Remember that polling at 30 seconds is the interval suggested in the docs.
- HTTPS only.
- Idempotent handlers.
- Log job ids.
Sources
Related posts
More in Developers
- callback_url or webhook_url: which field each Sume video route takes
POST /v1/videos takes callback_url; motion control, lip-sync and image routes take mode plus webhook_url. The field names and what they share.
- Cancel a wrong video job after a Sora port: only before it starts
Ported prompts on the wrong model burn money. Sume cancels a video job only before generation starts; later you get 409 job_generation_already_started.
- Cancel a Format run: cancel_effect canceled vs no_op, and the bill
Cancel is idempotent. cancel_effect says canceled or no_op, a canceled run never sends a webhook, and generation that finished is still billed.
- Cap Sume spend from an agent loop: dry_run, max_spend_usd and run caps
Four optional guards cap what an automated Sume caller can spend: dry_run, max_spend_usd, generation_spend_cap_usd on Formats, and a balance check.
Written by Sume