n8n WEBHOOK_URL deprecated in 2.35: the URL Sume will accept
n8n 2.35.0 deprecates WEBHOOK_URL for N8N_WEBHOOK_URL. Sume only calls public HTTPS webhook URLs, so a wrong base URL fails at submit. How to set and test it.

On a self-hosted n8n, set N8N_WEBHOOK_URL to your public HTTPS base address; n8n's endpoint docs say WEBHOOK_URL is deprecated from n8n 2.35.0 as an alias of it and still works but logs a warning at startup. This matters for Sume because the webhook URL you give a job must be public HTTPS, and n8n builds the URLs it shows you from this variable.
If n8n sits behind a proxy and has no base URL set, the Production URL it displays may not be one Sume can reach. A bad URL does not fail silently: Sume's docs say localhost, private-network and non-HTTPS webhook URLs are rejected.
Which n8n variables decide the webhook address?
n8n's table describes N8N_WEBHOOK_URL as the variable that sets the base URL for test and production webhooks behind a reverse proxy, and marks WEBHOOK_URL as a deprecated alias of it.
| Variable | Default | What it controls |
|---|---|---|
| N8N_WEBHOOK_URL | none | Base URL for test and production webhooks behind a reverse proxy |
| WEBHOOK_URL | none | Deprecated from 2.35.0; alias of N8N_WEBHOOK_URL (still works, logs a warning at startup) |
| N8N_ENDPOINT_WEBHOOK | webhook | Path for production webhooks |
| N8N_ENDPOINT_WEBHOOK_TEST | webhook-test | Path for test webhooks |
| N8N_ENDPOINT_WEBHOOK_WAIT | webhook-waiting | Path for waiting webhooks |
What does Sume check before it accepts the URL?
The job webhook docs say webhook URLs must be public HTTPS URLs, and localhost, private-network and non-HTTPS URLs are rejected. For Format, Action and Agent runs, the run webhooks docs add a 2048-character limit, re-validation at delivery time, and no redirect following: a 3xx is not a delivery.
Use the production path, not the test one: the two have separate paths (webhook and webhook-test by default), and a job that finishes minutes later should call the production address.
What goes wrong behind a reverse proxy?
The classic failure is a workflow that works from the editor and never receives a callback. Common causes are a base URL that still names localhost or an internal hostname, a plain http address, and a proxy rule that redirects. Each one maps to a Sume outcome you can see: the first two are rejected at submit, and the third shows up as undelivered attempts in the job's events.
Work through them in order. Open the Production URL n8n shows in the Webhook node and read the host. If it is not the public name you expect, fix N8N_WEBHOOK_URL and restart. Then call the URL yourself with curl from outside your network. Only then submit a Sume job. This costs nothing until the last step, and the last step can be an inexpensive image.
How do I check it end to end?
Submit a cheap image job with your n8n production URL as webhook_url, then read the job's events. The webhook.delivery event shows what Sume tried. Replace the host and path with your own.
curl -sS -X POST https://api.sume.com/v1/image-1.0/generate \
-H "Authorization: Bearer $SUME_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: n8n-url-check-001" \
-d '{"prompt":"a plain white square","mode":"webhook","webhook_url":"https://n8n.example.com/webhook/sume-done"}'
curl -sS https://api.sume.com/v1/jobs/JOB_ID/events \
-H "Authorization: Bearer $SUME_API_KEY"Does the n8n version matter?
Only for the variable name. The deprecation note in n8n's table says WEBHOOK_URL still works from 2.35.0 but logs a warning at startup, so an existing deployment keeps running. Rename it when you next touch your configuration, and update any container or compose file that sets the old name, so a later removal does not surprise you. Check n8n's release notes for when that happens, because the page I read does not give a removal date.
Nothing on the Sume side depends on the n8n version. Sume sees a URL, checks it is public HTTPS, and posts to it.
What else should the n8n workflow do?
Respond with a 2xx fast, then dedupe on job_id. Sume retries a failed delivery up to 10 times at a 30-second default spacing, with a 10-second timeout per attempt, and POST /v1/jobs/{job_id}/webhook/redeliver re-sends the real terminal event with a fresh signature. See Zapier Catch Raw Hook and the Sume signature for the same verification idea on another platform, and keep a status poll as a backup.
Sume does not call n8n Cloud and self-hosted instances differently; the only requirement is that the address is public HTTPS.
Sources
Related posts
More in Integrations
- OpenHands MCP server: add Sume as a Streamable HTTP server
Add Sume's hosted MCP to OpenHands as a Streamable HTTP server with a bearer API key, and know why OAuth does not suit unattended OpenHands runs.
- Perplexity Agent API MCP tool: connect Sume with allowed_tools
Perplexity's Agent API runs every MCP tool call with no approval step. Connect Sume's hosted MCP with an allowed_tools list so a model cannot reach paid tools.
- Pipedream Workflows shuts down March 31, 2027: move Sume calls
Pipedream says Workflows ends March 31, 2027. A Sume flow is HTTPS calls plus one signed webhook: rebuild those three parts elsewhere and poll in-flight jobs.
- Raycast MCP: add Sume's hosted server with Dynamic OAuth
Add Sume to Raycast as an HTTP MCP server: URL, Dynamic OAuth sign-in, read-only by default, and when to switch to an API-key header for paid tools.
Written by Sume