verifyWebhook toleranceSeconds 0 turns off the replay check

In @sume-com/sdk, toleranceSeconds defaults to 300 and 0 skips the timestamp check. Keep the default and use the now seam to test old deliveries.

4 min readSume
All posts

In @sume-com/sdk, verifyWebhook rejects a delivery whose timestamp is more than toleranceSeconds away from now, and the default is 300 seconds. Setting toleranceSeconds: 0 skips that check entirely, so a captured delivery would verify forever. Leave the default in production and use the now option when a test needs an old fixture.

What each option does

  • The Webhooks docs recommend rejecting callbacks outside a replay window and call five minutes a reasonable default.
verifyWebhook replay options (read 2026-10-06)
OptionDefaultEffect
toleranceSeconds300Reject timestamps further than this from now
toleranceSeconds: 0n/aNo timestamp check; signature only
nowcurrent Unix secondsTest seam to fake the clock
Missing or empty secretn/aReturns false

Test an old fixture without disabling the check

Pass a clock that matches the fixture's timestamp. The check stays on and your test stays honest.

import { verifyWebhook } from "@sume-com/sdk";

const fixtureTimestamp = 1_780_000_000;

const ok = await verifyWebhook({
  body: rawBody,
  headers: {
    "x-sume-webhook-timestamp": String(fixtureTimestamp),
    "x-sume-webhook-signature": signatureHeader,
  },
  secret: process.env.SUME_COM_WEBHOOK_SIGNING_SECRET ?? "",
  now: () => fixtureTimestamp + 5,
});
console.log(ok);

When a replay window still hurts

A server whose clock drifts by more than five minutes fails every delivery. Fix the clock rather than widening the window to hours. Remember that Redeliver sends a fresh timestamp and signature, so redelivered events do not need a wider window.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume