IPv6-only webhook endpoint: test Sume delivery before launch
OpenAI's API now accepts IPv6 connections. If your webhook host is IPv6-only, prove Sume can reach it with POST /v1/webhooks/test-deliveries first.

Do not guess whether your IPv6-only endpoint is reachable by Sume: send a test delivery to it. POST /v1/webhooks/test-deliveries posts a dummy signed webhook.test event to a URL you give it, and it needs no real job.
Why this comes up
OpenAI's changelog for Sep 1, 2026 says connections to api.openai.com now support the IPv6 protocol. Teams moving their own stack to IPv6 sometimes expose callback hosts that only have an AAAA record. The Sume docs do not state whether webhook delivery supports IPv6-only hosts, so treat it as unknown until you test it.
What the Sume docs do say
Webhook URLs must be public HTTPS URLs. Localhost, private-network and non-HTTPS URLs are rejected. Each attempt has a 10 second timeout, and a job gets up to 10 attempts in total, 30 seconds apart by default.
- Public HTTPS only, so no tunnels to a private address
- Any 2xx counts as accepted
- A slow endpoint burns the attempt budget
Run the test
The route needs an API key with account:write and takes a webhook_url. The response carries the status_code your endpoint returned. A 2xx proves the URL is reachable and your handler accepts the signed body; verify the signature in the handler to prove the secret as well.
import os, requests
resp = requests.post(
"https://api.sume.com/v1/webhooks/test-deliveries",
headers={"Authorization": f"Bearer {os.environ['SUME_API_KEY']}"},
json={"webhook_url": "https://hooks.example.com/sume"},
timeout=30,
)
print(resp.status_code)
print(resp.text)If it fails
Check these in order: the host answers on HTTPS from the public internet, the certificate is valid, the handler returns 2xx within 10 seconds, and the handler reads the raw body before parsing JSON. If an IPv6-only host fails while a dual-stack host with the same code passes, add an IPv4 address and re-test; then ask Sume support, quoting the request_id from the error body.
Pre-launch checklist
| Check | Why |
|---|---|
| Send test returns success | Proves the URL is reachable and your handler answers 2xx |
| Verify signature on raw body | Parsed JSON no longer matches what was signed |
| Return 2xx within 10 s | Attempt timeout is 10 s |
| Keep status polling | Delivery can still fail after 10 attempts |
After launch
Use Redeliver, POST /v1/jobs/{job_id}/webhook/redeliver, to replay a real terminal event with a fresh timestamp and signature. Send test never replays a real job.
Sources
Related posts
More in Developers
- Keep your Sora-style create_video() call: map it onto Sume
Sora's seconds, size and input_reference become duration, resolution plus aspect_ratio, and a first frame. Here is that map as a Python wrapper over Sume.
- Korean karaoke captions: korean-ad and language ko on Sume
Burn Korean karaoke-style captions with style korean-ad and language ko on /v1/video-captions: one phrase at a time, the spoken word in a heavier weight.
- Workers KV jurisdictions: keep Sume job records in region
Cloudflare made Workers KV jurisdictions generally available on Oct 2, 2026. Here is how to key Sume job_id records into a region-scoped namespace.
- LangGraph custom image: keep SUME_API_KEY out of it
langgraph-cli 0.4.32 adds an --image-uri flag for self-hosted custom containers. Inject SUME_API_KEY as a runtime env var; never bake it into the image.
Written by Sume