Cloudflare Worker roles: let an agent deploy a Sume webhook receiver
Cloudflare's four Worker roles let an agent token deploy a Sume webhook receiver without delete rights. Which role to give it and what Sume still needs.

Give a coding agent the Editor role if you want it to deploy a Worker that receives Sume webhooks but not delete it. Cloudflare's September 2026 changelog introduced four granular Worker roles: Metadata Read-Only, Content Read-Only, Editor and Admin. Editor can deploy without delete, which is the right shape for an agent that ships a receiver and should never remove production code.
The four roles
Per Cloudflare, the roles apply to members, User Groups and API tokens, and can be set through the dashboard, the API or Terraform. Durable Objects inherit the permissions of the Worker they belong to.
| Role | Intended reach |
|---|---|
| Metadata Read-Only | See Worker metadata only |
| Content Read-Only | Also read Worker content |
| Editor | Deploy changes, no delete |
| Admin | Full control including delete |
Why Editor fits a webhook receiver
A Sume webhook receiver is a small HTTPS handler. It verifies an HMAC-SHA256 signature over <timestamp>.<raw_body>, dedupes on job_id (or run_id for run events) and answers quickly, because each delivery attempt has a 10 second timeout and redirects are not followed. An agent can write and redeploy that code many times. Deleting it would silently stop your delivery path, and Sume would retry up to 10 times before giving up.
What the token does not cover
Cloudflare roles govern Cloudflare. They say nothing about Sume. The signing secret lives in the Sume dashboard Webhooks tab or at GET /v1/webhooks/signing-secret and needs the account:read scope. Store it as a Worker secret under the name SUME_COM_WEBHOOK_SIGNING_SECRET, and do not let the agent print it.
Rotating is a separate call, POST /v1/webhooks/signing-secret/rotate. For 24 hours the signature header carries more than one sume-v1= entry, so your receiver must accept any match.
- Give the Cloudflare token Editor, not Admin.
- Give the Sume key only the scopes the task needs.
- Never grant the agent permission to rotate the signing secret unattended.
Test the receiver end to end
Use POST /v1/webhooks/test-deliveries to send a signed test event to the Worker URL, then check the Worker logs. If a real event was missed, POST /v1/jobs/{id}/webhook/redeliver with the jobs:write scope replays it. The URL must be public HTTPS, so a workers.dev or custom domain route is fine and a private address is not.
Sources
Related posts
More in Developers
- Cloudflare Queues limits vs Sume queue_full 429: who retries?
Cloudflare Queues allows 100 retries and 24h delaySeconds. Sume answers 429 queue_full or rate_limited. How to back off in a consumer without duplicate jobs.
- Cloudflare Stream 200 MB upload limit: when you must use tus
Cloudflare Stream accepts basic uploads up to 200 MB and requires tus above that. Read the size from a Sume probe and route the file before you upload.
- Cloudflare Workflows step.sleep and a Sume job: poll without steps
Cloudflare Workflows step.sleep does not count toward the step limit, so a Sume job poll loop can wait cheaply. Limits, a loop shape and the retention catch.
- Codex 0.160 queued messages resume after reconnect: Sume safety
Codex 0.160 resumes unsent queued messages after a reconnect without duplicate sends. That covers messages, not tool effects, so keep Sume idempotency_key.
Written by Sume