Sume webhook secret rotation: why the header has two sume-v1 entries

During a signing-secret rotation Sume sends one sume-v1 entry per live secret, newest first, comma separated. Accept the delivery if any entry matches.

4 min readSume
All posts

During a signing-secret rotation the signature header carries one entry per live secret, newest first, separated by commas: sume-v1=<new>,sume-v1=<previous>. Accept the delivery when any entry matches (read 2026-10-06 in the webhook docs).

How should a receiver handle it?

Split the header on commas, trim each entry, ignore any that do not start with sume-v1=, and compare each against your expected digest.

What should I do in practice?

A verifier that reads only one entry will fail during the rotation window.

  • Compare every entry so timing does not reveal which one matched.
  • Do not take only the first entry.
  • Deploy the new secret to your receiver before you rely on it.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume