Luma callback: 3 retries, 5 s timeout, vs Sume webhooks
Luma retries a failed callback at most 3 times with a 5-second timeout. Sume retries job webhooks up to 10 times with a 10-second timeout and signs each body.

Luma's Ray 2 callback endpoint must return 200, is retried at most 3 times, and has a 5-second timeout, per its video generation docs. Sume's job webhooks retry up to 10 attempts in total, wait 10 seconds per attempt, space attempts 30 seconds apart by default, and sign the raw body so you can verify it.
Side by side
The two schemes differ in how forgiving they are of a slow receiver.
| Rule | Luma Ray 2 | Sume job webhook |
|---|---|---|
| Success | Return 200 | Any 2xx response |
| Retries | Max 3 | Up to 10 attempts total |
| Timeout | 5 seconds | 10 seconds per attempt |
| Spacing | 100 ms delay | Fixed delay, 30 s by default |
| Image inputs | Your own CDN URLs | Public HTTPS URLs |
Design for the short timeout
A 5-second budget is tight if your handler writes to a database or calls another service before it replies. The fix is the same on either platform: store the event, return success, and process later. Sume's docs say to return any 2xx after durably storing the event and to use job_id as your idempotency key.
Submitting in webhook mode
Send mode: webhook with a public HTTPS webhook_url. Sume signs the raw JSON body with HMAC SHA-256 over <timestamp>.<raw_body> and sends x-sume-webhook-timestamp and x-sume-webhook-signature headers. Reject a timestamp outside your tolerance window, five minutes by default.
Keep a polling fallback
Webhook delivery is an optimization, not the only way to learn the result. Keep polling status_url available for events that never arrive. If you instead use sync or subscribe on a video job, wait_timeout_seconds is bounded to 0 to 30 seconds and the job usually outlasts it, so continue with the status URL and do not resubmit.
curl -X POST https://api.sume.com/v1/video-router/generate \
-H "Authorization: Bearer $SUME_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: webhook-demo-001" \
-d '{"model":"seedance-2.5","prompt":"A slow pan across a desk","duration":8,"mode":"webhook","webhook_url":"https://example.com/hooks/sume"}'Sources
Related posts
More in Developers
- MCP 2026-07-28 deprecations: SSE, sampling, roots, logging checklist
MCP 2026-07-28 deprecates Roots, Sampling and Logging and reclassifies HTTP+SSE as Deprecated, with 12 months of notice. A checklist for media servers.
- MCP deprecations, removal from July 2027: audit Sume client
An MCP 2026-07-28 release candidate deprecates Roots, Sampling, Logging, Dynamic Client Registration and HTTP+SSE, removal no earlier than July 28, 2027.
- MCP OAuth without DCR: client ID metadata documents and issuer checks
MCP 2026-07-28 deprecates dynamic client registration for Client ID Metadata Documents and requires clients to validate iss. What it means for Sume.
- Python MCP SDK 2.3 subscriptions=False: a Sume wrapper that pulls
MCPServer(subscriptions=False) turns off push subscriptions in the Python SDK. A wrapper over Sume jobs can do without them by waiting in bounded slices.
Written by Sume