Sume webhook signature will not verify: compare the fingerprint

Each Sume delivery has x-sume-webhook-secret-fingerprint. Compare it with the dashboard fingerprint to find a wrong secret without ever sending the secret.

4 min readSume
All posts

Every Sume delivery carries x-sume-webhook-secret-fingerprint, and the receipt's webhook_delivery.signing_secret_fingerprint shows the same value. If a signature does not verify, compare it with the fingerprint next to the secret in the dashboard (read 2026-10-06).

How do I debug a mismatch?

A different fingerprint means your receiver holds the wrong secret. The same fingerprint means the problem is in how you build the signed string, usually a re-serialized body.

What should I do in practice?

The latter needs an API key with account:read.

  • Neither side needs to send the secret itself.
  • Sign <timestamp>.<raw_body> exactly.
  • Read the secret from the Webhooks tab or GET /v1/webhooks/signing-secret.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume