Google Cloud Workflows callback needs an IAM token: relay Sume
A Cloud Workflows callback URL needs the workflows.callbacks.send permission and a Bearer token. Sume webhooks cannot carry one, so relay after verifying.

Do not register the Cloud Workflows callback URL as the Sume webhook_url. Google's page says the caller needs the workflows.callbacks.send IAM permission and sends an Authorization: Bearer token, and the Sume docs document no custom headers on delivery, so a verified relay should make the callback.
Sume facts are from the Webhooks docs; the Google text was read 2026-09-30.
What does a callback require?
Google says the callback URL can be used to trigger the callback from a process external to the workflow, that the default method is POST, and that callers need workflows.callbacks.send. The await_callback timeout default is 43200 seconds, which is 12 hours.
| Topic | Google callback | Sume delivery |
|---|---|---|
| Auth | Bearer token with IAM permission | sume-v1 HMAC signature headers |
| Method | POST by default | POST to a public HTTPS URL |
| Wait ceiling | 43200 seconds by default | Up to 10 attempts on failure |
What does the relay send?
After it verifies the signature, the relay posts to the stored callback URL with a token for a service account that has the permission. This shell form shows the request; build the token however your platform does.
curl -X POST "$CALLBACK_URL" \
-H "Authorization: Bearer $(gcloud auth print-access-token)" \
-H "Content-Type: application/json" \
-d '{"job_id":"job_123","event":"job.completed"}'Where does the callback URL come from?
Keep the callback URL your workflow is waiting on, and store it against the Sume job id when you submit. When job.completed arrives, look the URL up by job_id, which is the idempotency key for job events.
What if the workflow times out first?
The Sume job is unaffected; a timeout on your side does not cancel it. Read the result with the job id afterwards and never resubmit the paid request.
Sources
Related posts
More in Developers
- google/veo-3.1 style ids vs Sume: bare video model ids
OpenRouter names video models org/slug, such as google/veo-3.1. Sume uses bare catalog ids like seedance-2 and never a provider prefix. How to port an id.
- GPT Image 2.5 1080x1350: why the size fails and what to send
1080x1350 breaks GPT Image 2.5's multiple-of-16 size rule. 1080 is not a multiple of 16. 1088x1360 (exact 4:5) meets the listed rules. Per OpenAI and Sume docs.
- GPT Image 2.5 Batch API: not supported, so fan out jobs
OpenAI's model page lists Batch as unsupported for GPT Image 2.5. On Sume, submit many async or webhook jobs to /v1/images and collect the results.
- GPT Image 2.5 mask edit: does the mask need an alpha channel?
OpenAI's API says the mask must contain an alpha channel. Sume's docs list a public HTTPS mask_url for GPT Image 2.5 edits but state no mask format rule.
Written by Sume