Sume webhook secret fingerprint header: check your secret safely
Every Sume run webhook carries x-sume-webhook-secret-fingerprint. Compare it to the receipt and dashboard fingerprint to catch a wrong secret before verifying.

Sume sends an x-sume-webhook-secret-fingerprint header on each run webhook. It matches webhook_delivery.signing_secret_fingerprint on the run receipt and the fingerprint shown in the dashboard, so you can tell whether your handler holds the right secret without ever logging the secret.
This follows Sume's Run webhooks and Agent Completions pages, read 2026-10-06.
How does verification work?
The signature is HMAC-SHA256 over <timestamp>.<raw_body>. Headers are x-sume-webhook-timestamp and x-sume-webhook-signature: sume-v1=.... A verifier must use the raw body, and must refuse an empty secret.
import hashlib
import hmac
def verify(secret: str, timestamp: str, raw_body: bytes, header: str) -> bool:
if not secret:
raise ValueError("empty signing secret")
msg = timestamp.encode() + b"." + raw_body
digest = hmac.new(secret.encode(), msg, hashlib.sha256).hexdigest()
return hmac.compare_digest("sume-v1=" + digest, header)Where does the fingerprint help?
The fingerprint is not the secret, so logging it is safe.
- After rotating a secret, a mismatch tells you the deploy still has the old one.
- Signature failures can be a wrong secret or a re-serialized body; the fingerprint separates the two.
- Fetch the secret with
GET /v1/webhooks/signing-secret, which needsaccount:read.
Sources
Related posts
More in Developers
- Sume webhook signature header: why a sume-v2 entry is skipped
A Sume webhook verifier should compare only sume-v1= entries from the comma-separated header and skip other prefixes. Here is a Python check with a test.
- Sume webhook signature mismatch? Check the secret fingerprint header
Each Sume delivery carries x-sume-webhook-secret-fingerprint. Compare it with the dashboard before debugging code. Python verifier that refuses an empty secret.
- Sume webhook secret is per workspace: read it with account:read
Sume derives the webhook signing secret per workspace, not as a shared platform value. Read it on the dashboard or with GET /v1/webhooks/signing-secret.
- SvelteKit +server.ts endpoint for an AI video webhook: request.text()
A SvelteKit POST handler reads request.text(), verifies Sume's HMAC over timestamp.body with node:crypto and returns 401 for bad or missing signatures.
Written by Sume