Sume webhook_url must be public HTTPS: localhost and http are rejected
Sume rejects localhost, private-network and non-HTTPS webhook URLs. Test local receivers through a public HTTPS tunnel or poll the job instead.

Webhook URLs must be public HTTPS URLs; the API rejects localhost, private-network and non-HTTPS URLs (read 2026-10-06 in the webhook docs).
How do I test a receiver on my laptop?
Expose it through a public HTTPS tunnel, or skip webhooks in development and poll the job's status_url. Both are supported communication modes.
What should I do in practice?
A rejected URL fails at submit time, not later.
- Send
mode: "webhook"withwebhook_url. - Keep the poll fallback in production too.
- Use Send test to check reachability first.
Sources
Related posts
More in Developers
- Sume webhook vs async polling vs sync vs subscribe: pick a mode
Sume has four communication modes: async, sync, webhook and subscribe. Webhook is best for servers, but keep the poll fallback for lost deliveries.
- SvelteKit +server.ts endpoint for an AI video webhook: request.text()
A SvelteKit POST handler reads request.text(), verifies Sume's HMAC over timestamp.body with node:crypto and returns 401 for bad or missing signatures.
- Swap the AI image model without a redeploy: JSON config hot reload
Read the Sume image model id from a JSON file that reloads when it changes, so a gpt-image-1 shutdown fix is a one-line edit with no deploy. Python, stdlib.
- Sweep for missed Sume webhooks: list queued and processing jobs
A webhook is an optimization. Run a periodic sweep over GET /v1/jobs with status=queued and processing, then compare against your own records and re-check each.
Written by Sume