OpenRouter video webhooks vs Sume callback_url, signing, retries
OpenRouter's video guide points to a webhooks cookbook. On Sume, pass an HTTPS callback_url, verify x-sume-webhook-signature, retry with Idempotency-Key.

OpenRouter's video guide mentions a cookbook covering handling webhooks. On Sume, the same job accepts a per-request callback_url (HTTPS only); Sume POSTs its standard job webhook envelope once the job is terminal, signed with x-sume-webhook-signature, and you retry safely by sending Idempotency-Key.
OpenRouter's side is a one-line mention in its guide, so this post does not describe its payloads. Sume facts are from the video generation docs, read 2026-10-01.
What does Sume send to my callback?
Pass callback_url in the request body. Sume POSTs to it when the job reaches a terminal state. The payload is Sume's job webhook envelope, not OpenRouter's video.generation.* envelope, so a handler written for OpenRouter's events needs its own branch.
How is it signed?
Sume signs the raw JSON body and sends x-sume-webhook-timestamp and x-sume-webhook-signature headers. Verify against the raw bytes you received, not a re-serialized object, and refuse to run if your signing secret is empty. The exact verification steps are in the webhooks guide linked from the docs.
| Item | Sume behavior |
|---|---|
| Where set | callback_url in the request body |
| Scheme | HTTPS only |
| Signature header | x-sume-webhook-signature |
| Timestamp header | x-sume-webhook-timestamp |
| Envelope | Sume's standard job webhook envelope |
How do I retry safely?
Send Idempotency-Key on the create request; a replay returns the original job instead of starting a second paid one. Polling remains available beside webhooks: GET /v1/jobs/{id}/status and GET /v1/jobs/{id}/result.
What should I do?
Treat the webhook as a signal, then read the result from GET /v1/jobs/{id}/result so a missed delivery does not lose the result. Event-name mapping is covered in OpenRouter video webhook events vs Sume job events.
Sources
Related posts
More in Developers
- Punch-in zoom on video by API: crop or zoompan, no keyframes
Sume has no auto zoom switch. Use a crop op for a fixed punch-in or the allowlisted zoompan filter in a video-filter graph; there are no keyframes.
- remove.bg API rate limit: 500 per minute, weighted by megapixels
remove.bg allows 500 images per minute at about 1 MP, less for larger inputs. Sume limits requests per minute per key and sends retry-after on 429.
- remove.bg bg_color replacement: Sume RMBG gives a transparent PNG
remove.bg's API has bg_color and bg_image_url. Sume RMBG 1.0 takes only an image_url and returns a PNG with alpha, so the new background is a second step.
- remove.bg crop and roi parameters: what Sume RMBG does instead
remove.bg has crop, roi, crop_margin, scale and position. Sume RMBG takes an image_url only and rejects other fields, so cropping happens before or after.
Written by Sume