Sume webhook Redeliver gets a fresh signature: dedupe on job_id

Redeliver re-POSTs a job's real terminal event with a new timestamp and signature, so dedupe on job_id and event, never on the signature or timestamp.

4 min readSume
All posts

When you redeliver a Sume job webhook, the real terminal event is sent again with a fresh timestamp and a fresh signature. Because both change, a receiver that dedupes on the signature or the timestamp will process the same job twice. Dedupe on job_id plus event, as the Webhooks docs advise: treat job_id as the idempotency key.

What changes and what stays

A redelivery compared with the original (read 2026-10-06)
FieldSame as original?
event, job_id, request_idYes
Payload (artifacts or error)Yes, the job's real terminal state
x-sume-webhook-timestampNo, fresh
x-sume-webhook-signatureNo, fresh
Destination URLYes. A new URL is a new job

A dedupe key that survives

Store the key durably before you return 2xx, with a unique constraint if you use a database.

seen: set[tuple[str, str]] = set()

def first_time(event: dict) -> bool:
    key = (event["job_id"], event["event"])  # not the signature, not the timestamp
    if key in seen:
        return False
    seen.add(key)
    return True

e = {"job_id": "job_1", "event": "job.completed"}
print(first_time(e), first_time(e))  # True False

Redeliver does not use the automatic budget

It works after the 10 automatic attempts are used, and it is not counted among them. So a receiver should expect the same event more than once across its lifetime.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume