Tavus S3 key_template vs Sume mirrored media URLs for clips
Tavus added an S3 key_template on Sep 24, 2026. Sume avatar outputs are mirrored to media.sume.com URLs. How to get finished clips into your own bucket.
Tavus's changelog for September 24, 2026 adds an S3 key_template, which controls where recordings land in your bucket. Sume has no such setting: avatar video outputs are mirrored to media.sume.com URLs, and you copy them to your own storage when the job finishes. A signed webhook for job.completed is the cleanest trigger.
The two approaches
Tavus lets you name the destination; Sume gives you a URL to fetch.
| Fact | Value |
|---|---|
| Tavus | S3 key_template (Sep 24) |
| Sume | Mirrored media.sume.com URL in job result |
| Sume completion signal | job.completed webhook or /v1/jobs/:id/result |
A copy-on-complete handler
Verify the signature first. Sume signs webhooks with HMAC SHA256 over <timestamp>.<raw_body>; refuse to run with an empty secret. Then read the result URL and store it.
Only terminal events are delivered: job.completed, job.failed, job.canceled.
import hashlib, hmac, os, time
def verify(timestamp: str, raw_body: bytes, signature_header: str) -> bool:
secret = os.environ.get("SUME_WEBHOOK_SECRET", "")
if not secret:
raise RuntimeError("SUME_WEBHOOK_SECRET is not set")
if abs(time.time() - int(timestamp)) > 300:
return False
signed = timestamp.encode() + b"." + raw_body
digest = hmac.new(secret.encode(), signed, hashlib.sha256).hexdigest()
for entry in signature_header.split(","):
if hmac.compare_digest("sume-v1=" + digest, entry.strip()):
return True
return False
Notes
The timestamp arrives in x-sume-webhook-timestamp and the signature in x-sume-webhook-signature as sume-v1=<hex>; during a secret rotation the header can carry several entries, which the loop handles. See the webhooks docs. Name your stored object by job id so a redelivery overwrites instead of duplicating.
Download promptly and keep your own copy; do not rely on a third-party URL for long-term hosting.
Sources
Related posts
More in Developers
- Test a Sume webhook receiver with node:test and signed fixtures
Three node:test cases that sign their own Sume webhook bodies: fresh, rotation header, and the three rejections. Runs with node --test.
- TikTok API posting: your app must not add a watermark or promo text
TikTok's guidelines say apps must not add a brand name, logo, watermark, link or promo text to posted content. What that means for an AI video pipeline.
- TikTok Content Posting API rate limits: 20, 6 and 30 per minute
TikTok limits creator info to 20 requests per minute, post init to 6, and status checks to 30, each per access token. Design your queue around the tightest one.
- TikTok Content Posting API changelog 2026: no posting changes listed
TikTok's developer changelog lists no Content Posting API entry in 2026; the latest are Data Portability and Research Tools. What to still re-check.
Written by Sume