Sume webhook Redeliver gets a fresh signature: dedupe on job_id
Redeliver re-POSTs a job's real terminal event with a new timestamp and signature, so dedupe on job_id and event, never on the signature or timestamp.

When you redeliver a Sume job webhook, the real terminal event is sent again with a fresh timestamp and a fresh signature. Because both change, a receiver that dedupes on the signature or the timestamp will process the same job twice. Dedupe on job_id plus event, as the Webhooks docs advise: treat job_id as the idempotency key.
What changes and what stays
| Field | Same as original? |
|---|---|
event, job_id, request_id | Yes |
| Payload (artifacts or error) | Yes, the job's real terminal state |
x-sume-webhook-timestamp | No, fresh |
x-sume-webhook-signature | No, fresh |
| Destination URL | Yes. A new URL is a new job |
A dedupe key that survives
Store the key durably before you return 2xx, with a unique constraint if you use a database.
seen: set[tuple[str, str]] = set()
def first_time(event: dict) -> bool:
key = (event["job_id"], event["event"]) # not the signature, not the timestamp
if key in seen:
return False
seen.add(key)
return True
e = {"job_id": "job_1", "event": "job.completed"}
print(first_time(e), first_time(e)) # True FalseRedeliver does not use the automatic budget
It works after the 10 automatic attempts are used, and it is not counted among them. So a receiver should expect the same event more than once across its lifetime.
Sources
Related posts
More in Developers
- Sume webhook retries last 270 to 370 seconds: when to poll
Sume tries a job webhook up to 10 times, 30 seconds apart, with a 10 second timeout each. That is about 4.5 to 6 minutes of retries before you must poll.
- Sume webhook retries for 4.5 minutes: dedupe on job_id in Python
Sume retries a webhook up to 10 times, 30 s apart. Make the effect happen once with a claim row keyed on job_id, shown in runnable Python with SQLite.
- Sume webhook rotation: upgrade the verifier before you click Rotate
During a rotation window Sume sends two signatures in one header. A receiver that compares the whole header for equality fails every delivery. Fix it first.
- Sume webhook secret fingerprint header: check your secret safely
Every Sume run webhook carries x-sume-webhook-secret-fingerprint. Compare it to the receipt and dashboard fingerprint to catch a wrong secret before verifying.
Written by Sume