Cloudflare Worker roles: let an agent deploy a Sume webhook receiver

Cloudflare's four Worker roles let an agent token deploy a Sume webhook receiver without delete rights. Which role to give it and what Sume still needs.

4 min readSume
All posts

Give a coding agent the Editor role if you want it to deploy a Worker that receives Sume webhooks but not delete it. Cloudflare's September 2026 changelog introduced four granular Worker roles: Metadata Read-Only, Content Read-Only, Editor and Admin. Editor can deploy without delete, which is the right shape for an agent that ships a receiver and should never remove production code.

The four roles

Per Cloudflare, the roles apply to members, User Groups and API tokens, and can be set through the dashboard, the API or Terraform. Durable Objects inherit the permissions of the Worker they belong to.

Cloudflare Worker roles (read 2026-10-02)
RoleIntended reach
Metadata Read-OnlySee Worker metadata only
Content Read-OnlyAlso read Worker content
EditorDeploy changes, no delete
AdminFull control including delete

Why Editor fits a webhook receiver

A Sume webhook receiver is a small HTTPS handler. It verifies an HMAC-SHA256 signature over <timestamp>.<raw_body>, dedupes on job_id (or run_id for run events) and answers quickly, because each delivery attempt has a 10 second timeout and redirects are not followed. An agent can write and redeploy that code many times. Deleting it would silently stop your delivery path, and Sume would retry up to 10 times before giving up.

What the token does not cover

Cloudflare roles govern Cloudflare. They say nothing about Sume. The signing secret lives in the Sume dashboard Webhooks tab or at GET /v1/webhooks/signing-secret and needs the account:read scope. Store it as a Worker secret under the name SUME_COM_WEBHOOK_SIGNING_SECRET, and do not let the agent print it.

Rotating is a separate call, POST /v1/webhooks/signing-secret/rotate. For 24 hours the signature header carries more than one sume-v1= entry, so your receiver must accept any match.

  • Give the Cloudflare token Editor, not Admin.
  • Give the Sume key only the scopes the task needs.
  • Never grant the agent permission to rotate the signing secret unattended.

Test the receiver end to end

Use POST /v1/webhooks/test-deliveries to send a signed test event to the Worker URL, then check the Worker logs. If a real event was missed, POST /v1/jobs/{id}/webhook/redeliver with the jobs:write scope replays it. The URL must be public HTTPS, so a workers.dev or custom domain route is fine and a private address is not.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume