Sume webhook secret is per workspace: read it with account:read

Sume derives the webhook signing secret per workspace, not as a shared platform value. Read it on the dashboard or with GET /v1/webhooks/signing-secret.

4 min readSume
All posts

Sume derives the webhook signing secret for your workspace, so it is yours and not a platform-wide value. You can read it on the Webhooks tab of the dashboard, or from GET /v1/webhooks/signing-secret with an API key that carries account:read. Job webhooks and run webhooks use that one secret, so a single verifier covers both.

Where each place fits

Ways to get the secret (read 2026-10-06)
WhereNeedsNote
Dashboard Webhooks tabA signed-in memberReveal, then copy
GET /v1/webhooks/signing-secretAPI key with account:readRead it at deploy time instead of pasting it
Environment variableYou set itUse SUME_COM_WEBHOOK_SIGNING_SECRET, the name the delivery worker uses

Read it from a script

Keep the value out of logs and shell history. The call needs only the scope named above.

curl -s https://api.sume.com/v1/webhooks/signing-secret \
  -H "Authorization: Bearer $SUME_API_KEY"

When a signature will not verify

Compare x-sume-webhook-secret-fingerprint on the delivery with the fingerprint shown next to the secret in the dashboard. Neither side has to send the secret. A mismatch usually means you hold another workspace's secret, or a secret from before a rotation.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume