GitHub wants a 2XX in 10 seconds, Sume times out at 10: dedupe both
GitHub and Sume both give a webhook receiver 10 seconds. GitHub reuses X-GitHub-Delivery on redelivery; with Sume, use job_id as the dedupe key.

Both GitHub and Sume expect your endpoint to answer within 10 seconds, so the same handler discipline works for each: verify, store, return 2xx, process later. The dedupe key differs. GitHub keeps the X-GitHub-Delivery header constant when a delivery is redelivered; Sume's documented key is the job_id in the body.
The table puts the two side by side. If your service receives both, give them different routes and do not share a dedupe table keyspace.
Side by side
| Item | GitHub | Sume |
|---|---|---|
| Response deadline | Respond with a 2XX within 10 seconds | 10 second timeout per attempt |
| Success | 2XX | Any 2xx once the event is stored durably |
| Redelivery marker | Same X-GitHub-Delivery header on redelivery | Same job_id; replay via POST /v1/jobs/{job_id}/webhook/redeliver |
| Dedupe key | X-GitHub-Delivery | job_id (receivers must treat it as the idempotency key) |
| Automatic retries | Not stated on the page I read | Up to 10 attempts, fixed 30 s apart |
| Signature | Not covered here | HMAC SHA-256 over timestamp.raw_body, header sume-v1=..., 300 s tolerance |
What redelivery looks like
With GitHub, the repeated delivery carries the same X-GitHub-Delivery value, so storing that value is enough to skip a repeat. With Sume, a redeliver call sends the real terminal event for that job with a fresh timestamp and signature, so the timestamp and signature change but job_id does not. Do not dedupe on the signature or timestamp.
One handler shape for both
- Read the raw body before parsing, keep it for signature checks.
- Insert the dedupe key into a table with a unique constraint. If it already exists, return 2xx and stop.
- Put the real work on a queue, then return 2xx. Do not call other APIs from inside the request.
- Remember that Sume's redeliver does not use one of the 10 automatic attempts, so a job can legitimately arrive again days later.
When 10 seconds is not enough
Treat a slow handler as a failed delivery for both services. For Sume, ten refused attempts still leave the job complete, so fall back to GET /v1/jobs/{id}/status and the result endpoint. Read the Sume webhooks docs for the fields.
Sources
Related posts
More in Developers
- Gitleaks custom rule for sume_live_ API keys, with pre-commit
Add a gitleaks rule that matches sume_live_ keys, run it as a pre-commit hook, and know what to do within minutes if a Sume key does leak.
- Go: decode a Sume WebP image with golang.org/x/image/webp
Go's image package decodes PNG and JPEG out of the box; WebP needs golang.org/x/image/webp. Decode a Sume image URL and read its size without a re-encode.
- Go client for a ported Sora worker: submit, poll, download
A standard-library Go program that submits to Sume POST /v1/videos, polls until the job is terminal, and saves the mp4. Replaces a Go wrapper around Sora.
- Go: poll a Sume job with a context deadline, next_poll_after_seconds
A Go net/http poller for Sume jobs: 20-minute context deadline, sleeps set by next_poll_after_seconds, stops on data.terminal. Standard library only.
Written by Sume