Send a signed webhook.test with POST /v1/webhooks/test-deliveries

Point POST /v1/webhooks/test-deliveries at a new HTTPS endpoint to get a signed webhook.test before any video job runs, then check the sume-v1 signature.

4 min readSume
All posts

Call POST /v1/webhooks/test-deliveries with a JSON body of {"webhook_url": "https://..."} and Sume sends one signed webhook.test event to that URL. It needs an API key with account:write, and it never replays a real job, so you can check your verifier before the first Seedance 2.5 clip finishes.

The URL must be public HTTPS. Localhost, private-network and non-HTTPS URLs are rejected.

How do I fire it?

The request body has one field. The body that arrives at your endpoint is a dummy payload with no job_id, so a receiver that dedupes on job_id must handle the missing key.

curl -X POST https://api.sume.com/v1/webhooks/test-deliveries \
  -H "Authorization: Bearer $SUME_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"webhook_url": "https://hooks.example.com/sume"}'

What does my endpoint receive?

Three headers matter: the timestamp, the signature and the secret fingerprint. The signature is HMAC-SHA256 over the timestamp, a dot, and the raw body, prefixed with sume-v1=.

Webhook test delivery (Sume docs, read 2026-10-09)
ItemValue
eventwebhook.test
x-sume-webhook-timestampUnix seconds
x-sume-webhook-signaturesume-v1=<hex>, comma-separated during a secret rotation
x-sume-webhook-secret-fingerprintCompare with the fingerprint on GET /v1/webhooks/signing-secret
job_idAbsent

How do I verify it in Python?

Refuse an empty secret outright, because an HMAC with an empty key still produces a valid-looking digest. Check every sume-v1 entry, since a rotation sends two.

import hashlib, hmac, time

def verify(raw: bytes, ts: str, header: str, secret: str, tol=300) -> bool:
    if not secret:
        raise ValueError("empty webhook secret")
    try:
        t = int(ts)
    except ValueError:
        return False
    if abs(time.time() - t) > tol:
        return False
    mac = hmac.new(secret.encode(), f"{t}.".encode() + raw, hashlib.sha256)
    want = "sume-v1=" + mac.hexdigest()
    return any(hmac.compare_digest(p.strip(), want) for p in header.split(","))

What should my endpoint answer?

Return a 2xx after you have stored the event, the same as for a real delivery. A slow endpoint spends the 10-second per-attempt budget, and a non-2xx answer is retried. For a test, a fast 204 is the right answer. Log the secret fingerprint header too; when a signature fails, comparing it with the fingerprint in the dashboard tells you whether you hold the wrong secret without anyone pasting the secret itself.

Where do I get the secret?

Reveal it on the Webhooks tab of the dashboard, or call GET /v1/webhooks/signing-secret with a key that has account:read. Keep it in an environment variable such as SUME_COM_WEBHOOK_SIGNING_SECRET, the name the delivery worker uses, and keep it out of source control.

Test or redeliver: which one?

The test call checks reachability and signing. To replay a real terminal event for a finished job, use POST /v1/jobs/{job_id}/webhook/redeliver instead. Neither one changes the destination URL stored on the job.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume