Supabase Edge Function secrets: 100 per project, 2 for Sume
Supabase allows 100 secrets per project. A Sume webhook receiver needs two: your API key and the webhook signing secret. Names, rules and what to verify.

Two secrets is all a Sume webhook receiver needs, so it barely touches Supabase's limit of 100 secrets per project: your Sume API key, and the webhook signing secret, which Sume documents under the name SUME_COM_WEBHOOK_SIGNING_SECRET.
Limits are from Supabase's Edge Functions limits page and Sume behavior from Job webhooks, both read 2026-10-01. See also a Supabase Edge Function video webhook.
What are the Supabase secret limits?
The page lists a maximum of 100 secrets per project and a maximum secret size of 48 KiB. It also lists a wall clock limit of 150s on Free and 400s on Paid, which is why a video job should finish by webhook, not by an open request.
| Limit | Value on the page |
|---|---|
| Secrets per project | 100 |
| Secret size | 48 KiB |
| Wall clock (Free / Paid) | 150s / 400s |
| Request idle timeout | 150s |
Which two secrets does a Sume receiver need?
The signing secret is read on the Webhooks tab of the dashboard or from GET /v1/webhooks/signing-secret with an API key carrying account:read. Store it as SUME_COM_WEBHOOK_SIGNING_SECRET, the same name the delivery worker signs with. The second is your Sume API key, used to submit jobs and to read status_url as a fallback.
Job webhooks and run webhooks share that one secret, so a single verifier covers both.
What must the function verify?
Sume signs HMAC SHA 256 over <timestamp>.<raw_body>. The SDK page says to pass the raw body: a parsed and reserialized object does not verify. In an Edge Function that means reading await request.text() before anything else. Reject callbacks when the timestamp is outside your replay window; the docs suggest five minutes.
Headers are x-sume-webhook-timestamp and x-sume-webhook-signature. During a secret rotation the signature header carries one sume-v1= entry per live secret, so accept the delivery if any entry matches.
What if the secret is missing or wrong?
Refuse to run with an empty secret. If a signature does not verify, compare x-sume-webhook-secret-fingerprint on the delivery with the fingerprint shown beside the secret in the dashboard, so neither side sends the secret itself. Return a 2xx only after storing the event, and use job_id as your idempotency key.
Sources
Related posts
More in Developers
- sync-3 image formats JPEG PNG WebP vs Sume image URL rules
sync-3 accepts JPEG, PNG and WebP stills. Sume's docs set URL rules instead: a fetchable public HTTPS image, with private and signed URLs rejected.
- sync-3 lip sync takes 10-15 min: async job and webhook pattern
Sync lists sync-3 at about 10-15 minutes for a 30 s video. Do not hold a request open: submit async, take a terminal webhook, and keep polling as a backup.
- Sync Labs batch API (20 to 500) vs Sume bulk runs (1 to 100)
Sync Labs batch takes 20 to 500 lip sync generations in one JSONL file on Scale and Enterprise. Sume bulk runs queue 1 to 100 Format runs with a 1 to 16 window.
- Sync Labs API rate limit: 100 per minute, and Sume headers
Sync Labs allows 100 POST /v2/generate and 600 GETs a minute. Sume has a per-plan requests-per-minute budget; read ratelimit headers and retry-after.
Written by Sume