Hookdeck Delivery Groups: per-tenant rates for Sume webhooks

Hookdeck Delivery Groups limit delivery rate per tenant. Use them to stop one account's burst of Sume completions starving others on a shared relay.

4 min readSume
All posts

If you relay Sume webhooks through Hookdeck to many downstream tenants, Delivery Groups are the new way to keep one noisy tenant from slowing the rest. Hookdeck's September 15, 2026 changelog entry describes them as stopping noisy neighbours with per-tenant delivery rates. Sume's side is unchanged: it posts to your URL, expects an answer within 10 seconds and retries up to 10 times.

Where the relay sits

Your Sume webhook URL points at Hookdeck. Hookdeck verifies, queues and forwards to each tenant's endpoint, absorbing slow consumers so Sume sees a fast 2xx.

Relay facts (read 2026-10-02)
ItemFact
Hookdeck Delivery GroupsPer-tenant delivery rates, Sep 15, 2026
Hookdeck CLIv3 released Sep 25, 2026
Sume attempt timeout10 s, no redirects
Sume job webhook spacingFixed 30 s
Sume run webhook spacingExponential, up to 1 h

What to group by

Group deliveries by the tenant that owns the work, not by Sume event type. A bulk run of 100 items produces a burst of format.run.terminal events for one tenant. A per-tenant rate smooths that burst on the way out, while other tenants keep their normal flow.

Keep a stable tenant id in your request metadata so the relay can route. Sume's receipt for run events carries the run_id you can use to join back to your own records.

Keep verification correct

Sume signs over <timestamp>.<raw_body> with HMAC-SHA256 and puts sume-v1=<hex> in x-sume-webhook-signature. If Hookdeck forwards the body unmodified, you can re-verify at the tenant. If it re-serialises JSON, the raw bytes change and the signature will not match, so verify at the relay edge and then authenticate relay to tenant by your own means.

  • Reject an empty signing secret.
  • Check the 300 second replay window against the timestamp header.
  • Accept any of several sume-v1= entries during a 24 hour rotation.

Dedupe downstream

A relay adds another retry layer on top of Sume's 10 attempts. Dedupe on job_id for job events and run_id for run events at each tenant. If a tenant misses events during an outage, POST /v1/jobs/{id}/webhook/redeliver or the format-run equivalent resends from Sume, and polling /status remains the backup.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume