Sume webhook replay protection: reject timestamps over 5 minutes old

Reject Sume webhook callbacks whose timestamp is outside your tolerance window. The docs suggest five minutes. Redeliveries carry a fresh timestamp.

4 min readSume
All posts

The x-sume-webhook-timestamp header lets you reject replays: drop callbacks whose timestamp is outside your tolerance window. Five minutes is the docs' suggested default (read 2026-10-06 in the webhook docs).

Will legitimate retries fail the check?

Each attempt is signed with a timestamp, and a Redeliver uses a fresh one, so a healthy receiver passes. Keep your server clock synced with NTP.

What should I do in practice?

Also dedupe on job_id.

  • Tolerance 300 seconds is the documented default.
  • A skewed clock rejects real deliveries.
  • The timestamp is part of the signed string.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume