Sume webhook replay protection: reject timestamps over 5 minutes old
Reject Sume webhook callbacks whose timestamp is outside your tolerance window. The docs suggest five minutes. Redeliveries carry a fresh timestamp.

The x-sume-webhook-timestamp header lets you reject replays: drop callbacks whose timestamp is outside your tolerance window. Five minutes is the docs' suggested default (read 2026-10-06 in the webhook docs).
Will legitimate retries fail the check?
Each attempt is signed with a timestamp, and a Redeliver uses a fresh one, so a healthy receiver passes. Keep your server clock synced with NTP.
What should I do in practice?
Also dedupe on job_id.
- Tolerance 300 seconds is the documented default.
- A skewed clock rejects real deliveries.
- The timestamp is part of the signed string.
Sources
Related posts
More in Developers
- Sume webhook_url must be public HTTPS: localhost and http are rejected
Sume rejects localhost, private-network and non-HTTPS webhook URLs. Test local receivers through a public HTTPS tunnel or poll the job instead.
- Sume webhook vs async polling vs sync vs subscribe: pick a mode
Sume has four communication modes: async, sync, webhook and subscribe. Webhook is best for servers, but keep the poll fallback for lost deliveries.
- SvelteKit +server.ts endpoint for an AI video webhook: request.text()
A SvelteKit POST handler reads request.text(), verifies Sume's HMAC over timestamp.body with node:crypto and returns 401 for bad or missing signatures.
- Swap the AI image model without a redeploy: JSON config hot reload
Read the Sume image model id from a JSON file that reloads when it changes, so a gpt-image-1 shutdown fix is a one-line edit with no deploy. Python, stdlib.
Written by Sume