verifyWebhook toleranceSeconds 0 turns off the replay check
In @sume-com/sdk, toleranceSeconds defaults to 300 and 0 skips the timestamp check. Keep the default and use the now seam to test old deliveries.

In @sume-com/sdk, verifyWebhook rejects a delivery whose timestamp is more than toleranceSeconds away from now, and the default is 300 seconds. Setting toleranceSeconds: 0 skips that check entirely, so a captured delivery would verify forever. Leave the default in production and use the now option when a test needs an old fixture.
What each option does
- The Webhooks docs recommend rejecting callbacks outside a replay window and call five minutes a reasonable default.
| Option | Default | Effect |
|---|---|---|
toleranceSeconds | 300 | Reject timestamps further than this from now |
toleranceSeconds: 0 | n/a | No timestamp check; signature only |
now | current Unix seconds | Test seam to fake the clock |
Missing or empty secret | n/a | Returns false |
Test an old fixture without disabling the check
Pass a clock that matches the fixture's timestamp. The check stays on and your test stays honest.
import { verifyWebhook } from "@sume-com/sdk";
const fixtureTimestamp = 1_780_000_000;
const ok = await verifyWebhook({
body: rawBody,
headers: {
"x-sume-webhook-timestamp": String(fixtureTimestamp),
"x-sume-webhook-signature": signatureHeader,
},
secret: process.env.SUME_COM_WEBHOOK_SIGNING_SECRET ?? "",
now: () => fixtureTimestamp + 5,
});
console.log(ok);When a replay window still hurts
A server whose clock drifts by more than five minutes fails every delivery. Fix the clock rather than widening the window to hours. Remember that Redeliver sends a fresh timestamp and signature, so redelivered events do not need a wider window.
Sources
Related posts
More in Developers
- 4K vertical Short in Timeline: the 2160 cap and 1214x2160
Timeline output width and height top out at 2160 and must be even, so 2160x3840 is refused. What the largest 9:16 frame is and whether a Short needs it.
- video_analyze or video_segment not in Sume tools_list? Dev host only
Sume's docs list video_analyze and video_segment as dev-only, shown only when a flag is on. On mcp.sume.com use video_inspect for what is in a clip.
- video_url on Sume video: only Omni edit, Genjutsu and Recast take it
On the Sume video API, video_url is a source clip, taken by gemini-omni-flash-1.1 (edit), higgsfield-genjutsu and h3-max-recast. Others use reference_video_u...
- Voice one script in six languages: Sume TTS loop and 409 guard
MAI-Voice-2.1 sells one voice across 23 languages. On Sume, set language per line, handle the 409 voice-language guard and price a six-language batch.
Written by Sume