Send a signed webhook.test with POST /v1/webhooks/test-deliveries
Point POST /v1/webhooks/test-deliveries at a new HTTPS endpoint to get a signed webhook.test before any video job runs, then check the sume-v1 signature.

Call POST /v1/webhooks/test-deliveries with a JSON body of {"webhook_url": "https://..."} and Sume sends one signed webhook.test event to that URL. It needs an API key with account:write, and it never replays a real job, so you can check your verifier before the first Seedance 2.5 clip finishes.
The URL must be public HTTPS. Localhost, private-network and non-HTTPS URLs are rejected.
How do I fire it?
The request body has one field. The body that arrives at your endpoint is a dummy payload with no job_id, so a receiver that dedupes on job_id must handle the missing key.
curl -X POST https://api.sume.com/v1/webhooks/test-deliveries \
-H "Authorization: Bearer $SUME_API_KEY" \
-H "Content-Type: application/json" \
-d '{"webhook_url": "https://hooks.example.com/sume"}'What does my endpoint receive?
Three headers matter: the timestamp, the signature and the secret fingerprint. The signature is HMAC-SHA256 over the timestamp, a dot, and the raw body, prefixed with sume-v1=.
| Item | Value |
|---|---|
| event | webhook.test |
| x-sume-webhook-timestamp | Unix seconds |
| x-sume-webhook-signature | sume-v1=<hex>, comma-separated during a secret rotation |
| x-sume-webhook-secret-fingerprint | Compare with the fingerprint on GET /v1/webhooks/signing-secret |
| job_id | Absent |
How do I verify it in Python?
Refuse an empty secret outright, because an HMAC with an empty key still produces a valid-looking digest. Check every sume-v1 entry, since a rotation sends two.
import hashlib, hmac, time
def verify(raw: bytes, ts: str, header: str, secret: str, tol=300) -> bool:
if not secret:
raise ValueError("empty webhook secret")
try:
t = int(ts)
except ValueError:
return False
if abs(time.time() - t) > tol:
return False
mac = hmac.new(secret.encode(), f"{t}.".encode() + raw, hashlib.sha256)
want = "sume-v1=" + mac.hexdigest()
return any(hmac.compare_digest(p.strip(), want) for p in header.split(","))What should my endpoint answer?
Return a 2xx after you have stored the event, the same as for a real delivery. A slow endpoint spends the 10-second per-attempt budget, and a non-2xx answer is retried. For a test, a fast 204 is the right answer. Log the secret fingerprint header too; when a signature fails, comparing it with the fingerprint in the dashboard tells you whether you hold the wrong secret without anyone pasting the secret itself.
Where do I get the secret?
Reveal it on the Webhooks tab of the dashboard, or call GET /v1/webhooks/signing-secret with a key that has account:read. Keep it in an environment variable such as SUME_COM_WEBHOOK_SIGNING_SECRET, the name the delivery worker uses, and keep it out of source control.
Test or redeliver: which one?
The test call checks reachability and signing. To replay a real terminal event for a finished job, use POST /v1/jobs/{job_id}/webhook/redeliver instead. Neither one changes the destination URL stored on the job.
Sources
Related posts
More in Developers
- Seven pre-flight checks before an Omni, H3 or Recast job
Duration, resolution, ratio, edit conflicts, reference counts, refused fields and URLs: seven per-model checks that catch a refused Sume video request.
- SGLang H3 /v1/videos vs Sume /v1/videos: same path, new fields
A self-hosted MiniMax H3 SGLang server and Sume both expose /v1/videos, but the fields differ: seconds vs duration, seed accepted vs not listed. Small adapter.
- Size a Sume submit wave: limit 100, 30 processing, 10 queued gives 60
How many new jobs can a Sume workspace take? max(0, limit - active - queued), capped by queue_capacity_remaining. Worked numbers and a TypeScript helper.
- Smoke-test 1:4, 4:1, 1:8 and 8:1 on Nano Banana 2.1 for $0.30
Four calls at 0.5K, one per new ratio, cost $0.30 on Sume ($0.80 at 4K). A script that prints status and cost per ratio, and what a 400 or 202 means.
Written by Sume