Rotating a webhook secret during a gradual deployment

Sume signs with both the new and old secret for 24 hours after rotation, so two receiver versions can run side by side. Upgrade the verifier first, then rotate.

4 min readSume
All posts

Yes, rotation can overlap a gradual deployment. For 24 hours after you rotate, Sume signs every delivery with both the new and old secret, so a receiver version holding either one still verifies. Upgrade the verifier before you rotate, then roll out the new secret.

Sume details are from Verifying webhooks, read 2026-09-30. Cloudflare's changelog describes how a gradual deployment appears in Workers Metrics; it says nothing about secrets, so the pairing here is an inference.

Why does a gradual deployment need an overlap?

Cloudflare's entry says a gradual deployment shows as one rollout, shading more as traffic shifts to the new version. For that stretch two receiver versions serve traffic. With one signature, a version holding the other secret rejects its share of deliveries.

What does each rollout step look like?

Cloudflare's entry says a rollout step records the traffic percentage configured at that step. Map your steps onto the window like this; the stages are my illustration, not from either vendor.

A rollout laid over the Sume rotation window, read 2026-09-30: https://docs.sume.com/sdk/webhooks
StageReceivers holding the old secretDo the deliveries verify?
Before rotatingAll of themYes, one signature
Rotated, 10% on the new secret90%Yes: the header carries both entries
50% on the new secret50%Yes, while the window is open
100% on the new secretNoneYes; the old entry is now spare
Window closes with a step unfinishedAny left behindNo: the old secret stops verifying

In what order should I do it?

First, make sure every receiver version verifies a multi-signature header. The docs warn that a hand-rolled check comparing the header for equality fails on every delivery during the window, and that verifyWebhook in @sume-com/sdk 0.2.0 already handles it. Second, rotate. Third, ship the new secret through your gradual rollout. Finish before the deadline, which the dashboard shows and rotation.previous_valid_until carries in the API responses.

Plan the rollout to fit well inside 24 hours. A rollout that you pause overnight at 50% is the case the window does not cover, so budget for the pause or rotate again later.

What if the secret leaked?

The window keeps the old secret valid, which is the point of a gradual rollout and the opposite of what a leak needs. The docs say rotating twice inside one window retires the secret from two rotations back immediately, which is what makes a leak stop. Weigh that against a half-finished rollout before you press the button a second time.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume