Deno 2.9.7 traceparent fix: tag a Sume job id in a Deno.serve log

Deno 2.9.7 extracts traceparent from Deno.serve regardless of header case. In a Sume webhook handler, log the job_id with the trace so a render is traceable.

4 min readSume
All posts

Deno 2.9.7 (September 2026) fixes Deno.serve so it extracts traceparent whatever the case of the header name (change #36840). A Sume webhook handler can then log the Sume job_id next to the trace and the delivery is findable from either side. Sume itself does not document a traceparent header on webhooks, so the trace id on a webhook comes from your own proxy or gateway, if any.

What the release says

The Deno releases page lists the fix as fix(ext/http): extract traceparent from Deno.serve regardless of header name case. HTTP header names are case-insensitive, and proxies differ in how they write them, so a case-sensitive lookup could miss the header and start a new trace.

Deno and Sume facts for a traced receiver, read 2026-10-08
ItemValue
Deno release2.9.7, September 2026
Changetraceparent read case-insensitively in Deno.serve
Sume signature headerx-sume-webhook-signature: sume-v1=<hex>
Sume timestamp headerx-sume-webhook-timestamp
Dedupe keyjob_id

A handler that logs both ids

verifyWebhook runs on Deno because it uses WebCrypto. Install it with an npm: specifier. The handler refuses to start without a secret.

import { verifyWebhook } from "npm:@sume-com/sdk@0.2.0";

const secret = Deno.env.get("SUME_COM_WEBHOOK_SIGNING_SECRET");
if (!secret) throw new Error("SUME_COM_WEBHOOK_SIGNING_SECRET is required");

Deno.serve(async (req) => {
  if (req.method !== "POST") return new Response(null, { status: 405 });
  const body = await req.text();
  const ok = await verifyWebhook({ body, headers: req.headers, secret });
  if (!ok) return new Response("bad signature", { status: 401 });
  const { event, job_id } = JSON.parse(body);
  const trace = req.headers.get("traceparent") ?? "none";
  console.log(JSON.stringify({ event, job_id, trace }));
  return new Response(null, { status: 204 });
});

What to log and what to skip

Log the event name, the job_id and the trace. Do not log the signature header or the secret. The fingerprint header is safe to log and tells you which secret signed the delivery.

  • Dedupe on job_id before work; Sume retries up to 10 times.
  • Return a 2xx within 10 seconds.
  • Use POST /v1/jobs/{job_id}/webhook/redeliver to replay a real event while you test.

Propagating the trace on your own calls

If your handler calls back into Sume, for example to fetch a job or start the next one, send the same traceparent on that request from your own code. Whether Sume echoes it is not documented in the pages read for this post, so keep your own log line as the link between the two systems and do not rely on a Sume-side trace.

A single log record with job_id and the trace id is enough to answer the main question during an incident: did the event reach us, and which request handled it.

Dedupe with Deno KV

Deno has a key-value store you can use for dedupe: write the job_id with a short expiry and skip work if it already exists. The Deno KV receiver post shows that pattern in full. Add the trace field to its log call and you have both.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume