GITHUB_TOKEN can't redeliver webhooks; Sume uses jobs:write
GitHub's built-in GITHUB_TOKEN cannot redeliver webhooks. For Sume job webhooks, a jobs:write API key calls POST /v1/jobs/{job_id}/webhook/redeliver instead.

GitHub's guide says the built-in GITHUB_TOKEN does not have sufficient permissions to redeliver webhooks and recommends a personal access token. Sume has no such limit to work around: POST /v1/jobs/{job_id}/webhook/redeliver needs only an API key with jobs:write, so a workflow can run it with a stored secret.
What does Sume redeliver do?
It re-POSTs that job's real terminal event (job.completed, job.failed or job.canceled) with a fresh timestamp and signature. It still works after automatic attempts are exhausted and does not consume one of the automatic 10. It does not change the destination URL; a new URL is a new job. Read 2026-10-01 in Job webhooks.
| Action | Endpoint | What it sends |
|---|---|---|
| Redeliver | POST /v1/jobs/{job_id}/webhook/redeliver (jobs:write) | The job's real terminal event, fresh signature |
| Send test | POST /v1/webhooks/test-deliveries (account:write) | A dummy signed webhook.test payload |
How do I know a delivery needs redelivery?
Delivery status is visible on the job object and in job events when available. The status values are pending, delivering, delivered, retrying, failed and exhausted. Automatic delivery makes up to 10 attempts total, with a fixed delay between attempts, 30s by default. Redeliver when the status is failed or exhausted.
What can go wrong?
The API returns 409 if the job is still running or was created without a webhook_url, and 404 for a job you cannot see. Your receiver must treat job_id as the idempotency key, because a redelivered event can arrive after one it already handled. For a step-by-step check, see debug a Sume webhook delivery.
Which key should the workflow hold?
Give the workflow a Sume API key scoped for jobs:write and keep it in your CI secret store. Keep status_url polling available too, since delivery is an optimization and never the only recovery path.
Sources
Related posts
More in Developers
- GeneratePMaxDraftCampaign IMAGE_ENABLED_GENERATE_PMAX_NOT_SUPPORTED
image_enabled=true on GeneratePMaxDraftCampaign returns IMAGE_ENABLED_GENERATE_PMAX_NOT_SUPPORTED in Ads API v25.2. Leave it false and add your own images.
- Google Cloud TTS caps requests at 5,000 bytes; Sume counts characters
Google lists 5,000 total bytes per request and says multi-byte characters such as ja-JP count toward it. Sume TTS 1.0 counts characters: up to 20,000.
- Google Chirp 3 allows 200 requests a minute; Sume limits by plan
Google lists per-minute request quotas by voice type: Chirp 3 at 200, Studio 500, Standard 1,000. Sume TTS is limited by workspace concurrency on your plan.
- Google Play AI content policy: the in-app report button
Google Play says apps that generate content with AI need in-app reporting or flagging that works without leaving the app. What that means for an AI video app.
Written by Sume