Sume rejects localhost webhook_url: develop locally with polling

Sume webhook URLs must be public HTTPS. localhost, private-network and non-HTTPS URLs are rejected. Develop with polling and Send test, then switch the URL on.

5 min readSume
All posts

Sume accepts only public HTTPS URLs as webhook_url. The API rejects localhost, private-network addresses and non-HTTPS URLs, so http://localhost:3000/hook fails at submit. For local development, submit with mode: "async" and poll. Add the webhook only when you have a public HTTPS endpoint to receive it.

What to do locally

The polling path needs no inbound connection. It also stays in production as a backup, since Sume's docs describe a webhook as a delivery optimization, not your only recovery path. Build and test the full completion flow against status_url and result_url first.

  • Submit with mode: "async" and keep the returned job id.
  • Poll GET /v1/jobs/{id}/status until terminal is true.
  • Fetch GET /v1/jobs/{id}/result when result_ready is true.

Testing the receiver separately

You can test the receiver code without a job. Run your handler locally and feed it a captured body, timestamp and signature, or deploy it to a public HTTPS host and use Send test from /dashboard/webhooks, which posts a signed webhook.test payload to a URL you type.

That checks the signature code and the secret. A real job event then only adds the payload fields.

Switching the webhook on

When the endpoint is public, change the submit to mode: "webhook" with webhook_url. Sending webhook_url or its alias callback_url without a mode also gives you webhook. The response is still 202 with the job envelope and poll URLs.

curl -X POST https://api.sume.com/v1/videos \
  -H "Authorization: Bearer $SUME_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: hook-test-001" \
  -d '{"model":"seedance-2","prompt":"A paper boat",
       "callback_url":"https://hooks.example.com/sume"}'

Keep the poll

Even in production, keep the poll available. Sume retries a refused delivery up to ten times, and Redeliver can resend an event on demand, but a sweep over open job ids is the simplest recovery for anything that slipped through.

Related posts

More in Developers

All Developers posts

Written by Sume