Python 3.15 lazy import in a Sume webhook handler: what to defer
Python 3.15 adds the lazy import keyword. In a Sume webhook receiver with a 10-second attempt budget, defer only the modules the signature check does not need.

In a Python 3.15 Sume webhook receiver, mark lazy import only the modules that the signature check and the durable write do not need, and keep the verifier's imports eager. A lazy import defers loading until the name is first used, and a missing or broken module then fails at that first use, which in a handler could be after you have already accepted the request. Sume gives each webhook attempt 10 seconds, and a slow endpoint burns the attempt budget and gets retried.
The language facts are from the What's New in Python 3.15 page, read 2026-10-03 while it was still labelled a release candidate; Sume's delivery numbers are from Webhooks and Run webhooks. I did not benchmark cold starts, so this post makes no speed claim.
How does lazy import work?
PEP 810 adds lazy as a soft keyword: lazy import json and lazy from pathlib import Path defer loading until the imported name is first used. It is allowed only at module scope; lazy inside a function, a class body or try/except/finally is a SyntaxError, and star imports and future imports cannot be lazy. You can also set it globally with -X lazy_imports or PYTHON_LAZY_IMPORTS, or list modules in __lazy_modules__ without changing the import lines.
| Form | Behavior |
|---|---|
lazy import json | Loads on first use of json |
lazy from pathlib import Path | Loads on first use of Path |
lazy inside a function | SyntaxError |
lazy in try or except | SyntaxError |
__lazy_modules__ = ["json"] | Plain import json becomes lazy |
-X lazy_imports or PYTHON_LAZY_IMPORTS | Global control |
What should stay eager in a webhook receiver?
Keep eager anything on the path from request to a 2xx: the HMAC and hash modules, the JSON parser, and your storage driver, so an import error shows up at process start and not in the middle of a delivery. Candidates for lazy are modules used only after you have replied, such as an image library for post-processing a downloaded artifact or a heavy reporting client.
The verifier itself does not change: HMAC-SHA256 over <timestamp>.<raw_body>, a replay window of five minutes by default, and any matching sume-v1= entry accepted during a secret rotation. Dedupe on job_id or request_id, and fetch the result from result_url or the job result endpoint if an event never arrives.
Sources
Related posts
More in Developers
- Python 3.15 UTF-8 default: still verify Sume webhooks on raw bytes
Python 3.15 makes UTF-8 the default for open() without an encoding. It does not change that a Sume signature covers raw body bytes, so verify before any parse.
- Python: list Sume video models that accept a video input
A 20-line Python script reads GET /v1/videos/models and prints every model whose supported_input_references include video_url, with its duration range.
- Python match on a Sume run status: terminal is not success
A Format run can be terminal as completed, failed, canceled or skipped. A structural match that never treats done as success, with a null-output case.
- Log x-sume-request-id and Idempotency-Key on every call (Python)
A requests response hook that writes one JSON log line per Sume call: x-sume-request-id, idempotency key, error code and rate-limit headers. Tested.
Written by Sume