Sume webhook secret fingerprint header: check your secret safely

Every Sume run webhook carries x-sume-webhook-secret-fingerprint. Compare it to the receipt and dashboard fingerprint to catch a wrong secret before verifying.

5 min readSume
All posts

Sume sends an x-sume-webhook-secret-fingerprint header on each run webhook. It matches webhook_delivery.signing_secret_fingerprint on the run receipt and the fingerprint shown in the dashboard, so you can tell whether your handler holds the right secret without ever logging the secret.

This follows Sume's Run webhooks and Agent Completions pages, read 2026-10-06.

How does verification work?

The signature is HMAC-SHA256 over <timestamp>.<raw_body>. Headers are x-sume-webhook-timestamp and x-sume-webhook-signature: sume-v1=.... A verifier must use the raw body, and must refuse an empty secret.

import hashlib
import hmac

def verify(secret: str, timestamp: str, raw_body: bytes, header: str) -> bool:
    if not secret:
        raise ValueError("empty signing secret")
    msg = timestamp.encode() + b"." + raw_body
    digest = hmac.new(secret.encode(), msg, hashlib.sha256).hexdigest()
    return hmac.compare_digest("sume-v1=" + digest, header)

Where does the fingerprint help?

The fingerprint is not the secret, so logging it is safe.

  • After rotating a secret, a mismatch tells you the deploy still has the old one.
  • Signature failures can be a wrong secret or a re-serialized body; the fingerprint separates the two.
  • Fetch the secret with GET /v1/webhooks/signing-secret, which needs account:read.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume