Sume webhook secret is per workspace: read it with account:read
Sume derives the webhook signing secret per workspace, not as a shared platform value. Read it on the dashboard or with GET /v1/webhooks/signing-secret.

Sume derives the webhook signing secret for your workspace, so it is yours and not a platform-wide value. You can read it on the Webhooks tab of the dashboard, or from GET /v1/webhooks/signing-secret with an API key that carries account:read. Job webhooks and run webhooks use that one secret, so a single verifier covers both.
Where each place fits
| Where | Needs | Note |
|---|---|---|
| Dashboard Webhooks tab | A signed-in member | Reveal, then copy |
GET /v1/webhooks/signing-secret | API key with account:read | Read it at deploy time instead of pasting it |
| Environment variable | You set it | Use SUME_COM_WEBHOOK_SIGNING_SECRET, the name the delivery worker uses |
Read it from a script
Keep the value out of logs and shell history. The call needs only the scope named above.
curl -s https://api.sume.com/v1/webhooks/signing-secret \
-H "Authorization: Bearer $SUME_API_KEY"When a signature will not verify
Compare x-sume-webhook-secret-fingerprint on the delivery with the fingerprint shown next to the secret in the dashboard. Neither side has to send the secret. A mismatch usually means you hold another workspace's secret, or a secret from before a rotation.
Sources
Related posts
More in Developers
- SvelteKit +server.ts endpoint for an AI video webhook: request.text()
A SvelteKit POST handler reads request.text(), verifies Sume's HMAC over timestamp.body with node:crypto and returns 401 for bad or missing signatures.
- Swap the AI image model without a redeploy: JSON config hot reload
Read the Sume image model id from a JSON file that reloads when it changes, so a gpt-image-1 shutdown fix is a one-line edit with no deploy. Python, stdlib.
- Sweep for missed Sume webhooks: list queued and processing jobs
A webhook is an optimization. Run a periodic sweep over GET /v1/jobs with status=queued and processing, then compare against your own records and re-check each.
- Test a Sume poll loop without waiting: inject sleep, assert delays
Unit test a job poll loop in milliseconds by injecting the fetch and the sleep. Assert that next_poll_after_seconds is obeyed and the 20-minute deadline holds.
Written by Sume