Sume video callback_url must be HTTPS: a webhook instead of polling

POST /v1/videos accepts callback_url, which must be HTTPS. Event names, the signature header, retries, and when a poll loop is still the safer choice.

5 min readSume
All posts

Add callback_url to a Sume video request if you want a push instead of a poll. The URL must be HTTPS. Sume's webhook docs list job.completed, job.failed and job.canceled events, signed with a header in the form sume-v1=<hex> computed over the timestamp, a dot and the raw body. Failed deliveries are retried up to 10 times, 30 seconds apart.

What your receiver must do

Requests carry x-sume-webhook-signature and x-sume-webhook-timestamp headers.

  • Read the raw body before any JSON parsing; the signature covers the raw bytes.
  • Refuse to verify when your signing secret is empty.
  • Reply 2xx quickly and do the work after.
  • Treat events as at-least-once and dedupe by job id.

Webhook or poll

Job statuses are pending, in_progress, completed, failed and cancelled; a poll loop should stop on any of the last three.

Choosing between callback_url and polling (read 2026-10-03)
SituationBetter choice
Public HTTPS endpoint you controlcallback_url
Script on a laptop or behind a firewallPoll GET /v1/videos/{id}
Cannot afford a missed eventBoth: webhook plus a sweeper that polls stuck jobs

Sources

Related posts

More in Developers

All Developers posts

Written by Sume