Sume Format webhook: verify the timestamp, register the final URL

Sume signs format.run.terminal with HMAC-SHA256, expects a response in 10 seconds, retries up to 10 times and does not follow redirects. Register the final URL.

5 min readSume
All posts

Sume signs the format.run.terminal webhook with HMAC-SHA256 over <timestamp>.<raw_body>. Reject any delivery whose timestamp is outside your tolerance window; the docs call five minutes reasonable. Answer within 10 seconds, because slower responses count as a failed attempt, and register the final URL, because Sume does not follow redirects. Dedupe on request_id. Sources: Webhooks and Formats errors and spend, read 2026-10-06.

What are the delivery rules?

The rules that decide whether your endpoint works.

Webhook delivery rules, read 2026-10-06 from docs.sume.com.
RuleValue
Signature headerx-sume-webhook-signature: sume-v1=<hex>
Timestamp headerx-sume-webhook-timestamp
Secret checkx-sume-webhook-secret-fingerprint
Response limit10 seconds
AttemptsUp to 10, backoff capped at one hour
RedirectsNot followed
Large receiptpayload is null when the receipt exceeds 1 MiB

What if a delivery failed?

Read the receipt at result_url, correct the endpoint, and send POST /v1/format-runs/{id}/webhook/redeliver. During a secret rotation the signature header carries one sume-v1= entry per live secret, so accept the delivery when any entry matches. If nothing verifies, compare the fingerprint header with the one on the receipt.

Sources

Related posts

More in Formats

All Formats posts

Written by Sume