Stripe allows 16 webhook endpoints; Sume takes a webhook URL per job

Stripe registers up to 16 endpoints. Sume has no registry: each job or Format run item carries its own public HTTPS webhook_url, signed with one secret.

5 min readSume
All posts

Stripe makes you register webhook endpoints ahead of time, and its webhook guide says you can register up to 16 of them. Sume does it the other way around: there is no endpoint registry. You send mode: "webhook" with a public HTTPS webhook_url on each generation submit, or a communication.webhook_url on each Format run item, and Sume signs every delivery with one per-workspace secret. The consequence is that routing is yours to design, and the design choices are different from Stripe's.

What per-request URLs give you

A per-job URL can carry context. Put the batch id and the row number in the path or query so your receiver can route without a lookup, for example https://hooks.example.com/sume/batch-42/row-7. Sume rejects localhost, private-network and non-HTTPS URLs, and an http:// address fails the submit with 400, so staging needs a public tunnel.

Redeliver does not change the destination: it re-posts the real terminal event to the URL stored on that job. A new URL is a new job. That is the opposite of editing an endpoint in Stripe's Workbench and clicking Resend.

Endpoint model comparison (read 2026-10-05)
QuestionStripeSume
Where URLs liveRegistered endpoints, up to 16On each job or run item
Event filteringChoose enabled event types per endpointTerminal events only, by design
Signing secretOne per endpointOne per workspace, shared by job and run webhooks
Local testingstripe listen forwards to localhostPublic HTTPS only; use a tunnel
Change a URLEdit the endpointSubmit a new job

Practical routing patterns

Keep one receiver and branch on the payload. Job webhooks arrive as job.completed, job.failed or job.canceled with a job_id. Run webhooks for Formats arrive as format.run.terminal with a request_id. Because the signature scheme is the same, one verifier fits both and the router is a switch on event.

In a Format bulk run the queue has no webhook, so each item carries its own communication.webhook_url. Reuse one receiver URL and tag the item with an identifier in the query string so the receiver can map a delivery back to a sheet row.

  • One receiver, one verifier, one table keyed by job_id or request_id.
  • Put routing context in the URL path, not in the body you do not control.
  • Never include secrets in the URL, since delivery logs record it.
  • Tell staging and production apart by hostname, because the secret is per workspace.

When 16 endpoints would be too few

Teams that embed Sume inside a multi-tenant product sometimes need one receiver per customer. With per-request URLs there is no cap to hit and nothing to provision, which removes a class of onboarding work, but it also means a bad URL is discovered at the first delivery, not at registration. Send a test delivery to each new URL first.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume