IPv6-only webhook endpoint: test Sume delivery before launch

OpenAI's API now accepts IPv6 connections. If your webhook host is IPv6-only, prove Sume can reach it with POST /v1/webhooks/test-deliveries first.

4 min readSume
All posts

Do not guess whether your IPv6-only endpoint is reachable by Sume: send a test delivery to it. POST /v1/webhooks/test-deliveries posts a dummy signed webhook.test event to a URL you give it, and it needs no real job.

Why this comes up

OpenAI's changelog for Sep 1, 2026 says connections to api.openai.com now support the IPv6 protocol. Teams moving their own stack to IPv6 sometimes expose callback hosts that only have an AAAA record. The Sume docs do not state whether webhook delivery supports IPv6-only hosts, so treat it as unknown until you test it.

What the Sume docs do say

Webhook URLs must be public HTTPS URLs. Localhost, private-network and non-HTTPS URLs are rejected. Each attempt has a 10 second timeout, and a job gets up to 10 attempts in total, 30 seconds apart by default.

  • Public HTTPS only, so no tunnels to a private address
  • Any 2xx counts as accepted
  • A slow endpoint burns the attempt budget

Run the test

The route needs an API key with account:write and takes a webhook_url. The response carries the status_code your endpoint returned. A 2xx proves the URL is reachable and your handler accepts the signed body; verify the signature in the handler to prove the secret as well.

import os, requests

resp = requests.post(
    "https://api.sume.com/v1/webhooks/test-deliveries",
    headers={"Authorization": f"Bearer {os.environ['SUME_API_KEY']}"},
    json={"webhook_url": "https://hooks.example.com/sume"},
    timeout=30,
)
print(resp.status_code)
print(resp.text)

If it fails

Check these in order: the host answers on HTTPS from the public internet, the certificate is valid, the handler returns 2xx within 10 seconds, and the handler reads the raw body before parsing JSON. If an IPv6-only host fails while a dual-stack host with the same code passes, add an IPv4 address and re-test; then ask Sume support, quoting the request_id from the error body.

Pre-launch checklist

Webhook pre-launch checks (read 2026-10-03)
CheckWhy
Send test returns successProves the URL is reachable and your handler answers 2xx
Verify signature on raw bodyParsed JSON no longer matches what was signed
Return 2xx within 10 sAttempt timeout is 10 s
Keep status pollingDelivery can still fail after 10 attempts

After launch

Use Redeliver, POST /v1/jobs/{job_id}/webhook/redeliver, to replay a real terminal event with a fresh timestamp and signature. Send test never replays a real job.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume