Python 3.15 lazy import in a Sume webhook handler: what to defer

Python 3.15 adds the lazy import keyword. In a Sume webhook receiver with a 10-second attempt budget, defer only the modules the signature check does not need.

5 min readSume
All posts

In a Python 3.15 Sume webhook receiver, mark lazy import only the modules that the signature check and the durable write do not need, and keep the verifier's imports eager. A lazy import defers loading until the name is first used, and a missing or broken module then fails at that first use, which in a handler could be after you have already accepted the request. Sume gives each webhook attempt 10 seconds, and a slow endpoint burns the attempt budget and gets retried.

The language facts are from the What's New in Python 3.15 page, read 2026-10-03 while it was still labelled a release candidate; Sume's delivery numbers are from Webhooks and Run webhooks. I did not benchmark cold starts, so this post makes no speed claim.

How does lazy import work?

PEP 810 adds lazy as a soft keyword: lazy import json and lazy from pathlib import Path defer loading until the imported name is first used. It is allowed only at module scope; lazy inside a function, a class body or try/except/finally is a SyntaxError, and star imports and future imports cannot be lazy. You can also set it globally with -X lazy_imports or PYTHON_LAZY_IMPORTS, or list modules in __lazy_modules__ without changing the import lines.

Lazy import rules from the Python 3.15 release candidate notes, read 2026-10-03.
FormBehavior
lazy import jsonLoads on first use of json
lazy from pathlib import PathLoads on first use of Path
lazy inside a functionSyntaxError
lazy in try or exceptSyntaxError
__lazy_modules__ = ["json"]Plain import json becomes lazy
-X lazy_imports or PYTHON_LAZY_IMPORTSGlobal control

What should stay eager in a webhook receiver?

Keep eager anything on the path from request to a 2xx: the HMAC and hash modules, the JSON parser, and your storage driver, so an import error shows up at process start and not in the middle of a delivery. Candidates for lazy are modules used only after you have replied, such as an image library for post-processing a downloaded artifact or a heavy reporting client.

The verifier itself does not change: HMAC-SHA256 over <timestamp>.<raw_body>, a replay window of five minutes by default, and any matching sume-v1= entry accepted during a secret rotation. Dedupe on job_id or request_id, and fetch the result from result_url or the job result endpoint if an event never arrives.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume