Verify a Sume Format webhook in Python with an empty-secret guard
Verify x-sume-webhook-signature in Python: HMAC-SHA256 over timestamp.raw_body, a five-minute window, constant-time compare, empty secret refused.

Sume signs each terminal webhook with HMAC-SHA256 over <timestamp>.<raw_body>. The signature header looks like sume-v1=<hex>, the timestamp is Unix seconds in x-sume-webhook-timestamp, and you should reject anything outside a five-minute window. Verify against the raw bytes, not a re-serialized JSON object, and refuse to run at all if the secret is empty: an empty secret makes every signature trivially forgeable.
Verifier
import hashlib, hmac, time
def verify(secret: str, timestamp: str, signature: str, raw_body: bytes) -> bool:
if not secret:
raise ValueError("webhook secret is empty")
try:
ts = int(timestamp)
except ValueError:
return False
if abs(time.time() - ts) > 300:
return False
msg = timestamp.encode() + b"." + raw_body
expected = "sume-v1=" + hmac.new(secret.encode(), msg, hashlib.sha256).hexdigest()
return hmac.compare_digest(expected, signature)Headers and dedupe
| Header | Use |
|---|---|
| x-sume-webhook-timestamp | Unix seconds, part of the signed string |
| x-sume-webhook-signature | sume-v1=<hex digest> |
| x-sume-webhook-secret-fingerprint | Identify which secret signed it |
Handle repeats
Deliveries retry, so dedupe on request_id or run_id before you act. Return a 2xx quickly and do the work after. The TypeScript SDK ships a verifyWebhook helper with the same rules; see SDK webhooks.
Sources
Related posts
More in Formats
- Sume SDK subscribeFormatRun: 20-minute timeout vs 90-minute runs
subscribeFormatRun in @sume-com/sdk polls every 2 seconds and times out at 20 minutes by default, while a Format run can live 90. Set the timeout on purpose.
- Shop Creative Hub limits: 50 per upload, 10k a month, batch math
Creative Hub for GMV Max takes 50 videos per upload and 10k a month. What that means for Sume bulk queues of 100, and where the 200-video link cap bites.
- Shorts ad copy: 40-character headline, 90-character description
Google recommends 40-character headlines and 90-character descriptions for the Shorts ad CTA card. Draft copy in bulk with Sume and check lengths before upload.
- Ready-made Formats for product video: the Sume Format catalog
Sume ships ready-made Formats for product and UGC-style video and images, each callable from your backend with one HTTP request at the reserved sume handle.
Written by Sume