HeyGen webhooks: 10 s ack, 24 h retries vs Sume's 10 attempts
HeyGen retries failed webhooks with exponential backoff for up to 24 hours after a 10 s timeout. Sume retries 10 times, 30 s apart. Read 2026-10-10.

HeyGen wants a 2xx within 10 seconds and retries failed deliveries with exponential backoff for up to 24 hours. Sume also allows 10 seconds per attempt, but it retries at a fixed delay (30 seconds by default) up to 10 attempts total, so its automatic window is minutes, not a day. After that, a Sume receiver recovers by polling or by asking for a redeliver.
HeyGen's side is from its Webhooks and Webhook Events pages, read 2026-10-10. Sume's side is the Webhooks page.
The delivery contracts
Both vendors say the same thing about your obligations: acknowledge fast, deduplicate, and do not trust delivery as the only path.
| Item | HeyGen | Sume |
|---|---|---|
| Success | 2xx within 10 seconds | Any 2xx, after you store the event durably |
| Per-attempt timeout | 10 seconds | 10 seconds |
| Retry schedule | Exponential backoff, up to 24 hours | Fixed delay, 30 s by default |
| Attempt cap | Not a count; bounded by the 24-hour window | 10 attempts total |
| Duplicates | A single event may arrive more than once | Treat job_id as the idempotency key |
| Dedupe key | event_data.video_id plus event_type, or callback_id | job_id |
| Endpoint | Public HTTPS URL | Public HTTPS URL; localhost and private networks rejected |
What the numbers mean in practice
Ten attempts at 30 seconds is roughly four and a half minutes of automatic retries after the first try (nine gaps of 30 seconds, assuming the default spacing and that each attempt fails fast). If your receiver is down for an hour, HeyGen's 24-hour window will usually still deliver once you are back. Sume will have given up, and the job will already be in its real terminal state.
That is why Sume's page keeps repeating the poll fallback. Every submit returns a status_url, and a completed avatar job can be read at GET /v1/jobs/{id}/result whenever you come back. A failed delivery is not a failed job.
Sume adds a lever HeyGen's pages do not describe: POST /v1/jobs/{job_id}/webhook/redeliver (scope jobs:write) re-sends the real terminal event with a fresh timestamp and signature, even after the automatic attempts are spent, and it does not consume one of the ten.
Design the receiver for the shorter window
- Return
2xxas soon as the event is stored. Do the download, transcode or publish step from a queue, not inside the request, so the 10-second budget is never spent on your own work. - Key your store on
job_idfor Sume and on the video id plus event type for HeyGen. Both vendors can send the same event twice. - Run a periodic sweep over jobs without a recorded terminal event and read their status. For avatar videos,
GET /v1/avatar-videos?status=processinglists in-flight ones, withlimitup to 100. - Verify the signature before you act. HeyGen specifies HMAC-SHA256 over the raw body in a
signatureheader; Sume signs<timestamp>.<raw_body>. Neither verifier should accept an empty secret.
Submitting an avatar job with a webhook
On Sume, add mode: "webhook" and a webhook_url to the talking-video request, or send only the URL, which selects webhook mode. Send an Idempotency-Key so a retried submit adopts the first job instead of billing a second one. Generate avatar video has the full body, and Jobs and results explains why polling stays in place beside a webhook.
One more difference worth planning for: HeyGen's Webhook Events page says the download URL in a success payload has a limited expiry window, so fetch and store the file promptly. Sume's webhook payload carries the artifacts of the finished job, with media.sume.com URLs, but you should still copy the finished clip into your own storage at the moment you verify the event, so that a later cleanup on either side never breaks a page that embeds it.
Finally, log the delivery outcome next to the job. Sume records webhook.delivery in the job events at GET /v1/jobs/{id}/events, which is the first place to look when a callback never arrived.
Sources
Related posts
More in Comparisons
- HeyGen webhook secret shown once: rotation vs Sume's reveal
HeyGen shows its webhook secret once and drops the old one on rotate. Sume lets you re-read it and signs with both secrets while rotating (read 2026-10-10).
- How long do Sume webhooks retry? About three hours vs Stripe
Sume makes up to 10 delivery attempts with exponential backoff capped at an hour, about three hours in all. Stripe retries for up to three days in live mode.
- Longest single shot per request: Vidu, Veo, Grok, Wan, Seedance
How long one request can run: Vidu Q4 16 s, Veo 8 s, Grok 15 s, Wan 3.0 and Seedance 2.5 30 s. Sume's matching row for each and the longest-shot cost.
- Luma Ray 2 5-second keyframes: Sume rows with start and end frames
Luma's API makes Ray 2 clips up to 5 s from start and end keyframes. Sume has no Luma row; these Sume rows accept both frames and cover a 5-second clip.
Written by Sume