n8n WEBHOOK_URL deprecated in 2.35: the URL Sume will accept

n8n 2.35.0 deprecates WEBHOOK_URL for N8N_WEBHOOK_URL. Sume only calls public HTTPS webhook URLs, so a wrong base URL fails at submit. How to set and test it.

5 min readSume
All posts

On a self-hosted n8n, set N8N_WEBHOOK_URL to your public HTTPS base address; n8n's endpoint docs say WEBHOOK_URL is deprecated from n8n 2.35.0 as an alias of it and still works but logs a warning at startup. This matters for Sume because the webhook URL you give a job must be public HTTPS, and n8n builds the URLs it shows you from this variable.

If n8n sits behind a proxy and has no base URL set, the Production URL it displays may not be one Sume can reach. A bad URL does not fail silently: Sume's docs say localhost, private-network and non-HTTPS webhook URLs are rejected.

Which n8n variables decide the webhook address?

n8n's table describes N8N_WEBHOOK_URL as the variable that sets the base URL for test and production webhooks behind a reverse proxy, and marks WEBHOOK_URL as a deprecated alias of it.

n8n endpoint variables, read 2026-10-02
VariableDefaultWhat it controls
N8N_WEBHOOK_URLnoneBase URL for test and production webhooks behind a reverse proxy
WEBHOOK_URLnoneDeprecated from 2.35.0; alias of N8N_WEBHOOK_URL (still works, logs a warning at startup)
N8N_ENDPOINT_WEBHOOKwebhookPath for production webhooks
N8N_ENDPOINT_WEBHOOK_TESTwebhook-testPath for test webhooks
N8N_ENDPOINT_WEBHOOK_WAITwebhook-waitingPath for waiting webhooks

What does Sume check before it accepts the URL?

The job webhook docs say webhook URLs must be public HTTPS URLs, and localhost, private-network and non-HTTPS URLs are rejected. For Format, Action and Agent runs, the run webhooks docs add a 2048-character limit, re-validation at delivery time, and no redirect following: a 3xx is not a delivery.

Use the production path, not the test one: the two have separate paths (webhook and webhook-test by default), and a job that finishes minutes later should call the production address.

What goes wrong behind a reverse proxy?

The classic failure is a workflow that works from the editor and never receives a callback. Common causes are a base URL that still names localhost or an internal hostname, a plain http address, and a proxy rule that redirects. Each one maps to a Sume outcome you can see: the first two are rejected at submit, and the third shows up as undelivered attempts in the job's events.

Work through them in order. Open the Production URL n8n shows in the Webhook node and read the host. If it is not the public name you expect, fix N8N_WEBHOOK_URL and restart. Then call the URL yourself with curl from outside your network. Only then submit a Sume job. This costs nothing until the last step, and the last step can be an inexpensive image.

How do I check it end to end?

Submit a cheap image job with your n8n production URL as webhook_url, then read the job's events. The webhook.delivery event shows what Sume tried. Replace the host and path with your own.

curl -sS -X POST https://api.sume.com/v1/image-1.0/generate \
  -H "Authorization: Bearer $SUME_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: n8n-url-check-001" \
  -d '{"prompt":"a plain white square","mode":"webhook","webhook_url":"https://n8n.example.com/webhook/sume-done"}'

curl -sS https://api.sume.com/v1/jobs/JOB_ID/events \
  -H "Authorization: Bearer $SUME_API_KEY"

Does the n8n version matter?

Only for the variable name. The deprecation note in n8n's table says WEBHOOK_URL still works from 2.35.0 but logs a warning at startup, so an existing deployment keeps running. Rename it when you next touch your configuration, and update any container or compose file that sets the old name, so a later removal does not surprise you. Check n8n's release notes for when that happens, because the page I read does not give a removal date.

Nothing on the Sume side depends on the n8n version. Sume sees a URL, checks it is public HTTPS, and posts to it.

What else should the n8n workflow do?

Respond with a 2xx fast, then dedupe on job_id. Sume retries a failed delivery up to 10 times at a 30-second default spacing, with a 10-second timeout per attempt, and POST /v1/jobs/{job_id}/webhook/redeliver re-sends the real terminal event with a fresh signature. See Zapier Catch Raw Hook and the Sume signature for the same verification idea on another platform, and keep a status poll as a backup.

Sume does not call n8n Cloud and self-hosted instances differently; the only requirement is that the address is public HTTPS.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume