Webhook signature mismatch: compare the secret fingerprint

Before filing a ticket for a Sume signature mismatch, compare the secret fingerprint header with the dashboard value. It is safe to paste into a ticket.

4 min readSume
All posts

Open the dashboard before you open a ticket. Match the x-sume-webhook-secret-fingerprint header of the failing request to the value beside your secret, and paste both into the ticket. Those two strings are shareable; the secret is not.

From Job webhooks and Verifying webhooks, read 2026-09-30.

What should the ticket contain?

Ticket checklist drawn from the Sume docs, read 2026-09-30: https://docs.sume.com/workflows/webhooks
ItemWhere it comes from
Fingerprint from the deliveryThe x-sume-webhook-secret-fingerprint header
Fingerprint from the dashboardWebhooks tab, beside the secret
Never includeThe secret itself

Why does the vendor world care about this?

Svix's September 2026 changelog describes customers debugging failed deliveries by reading attempts, payloads and responses from their editor without leaving it. The same instinct applies here: support can only help with what you can paste, and a fingerprint is pasteable while the secret is not.

What does a mismatch mean?

Two different values mean the receiver loaded another secret, often a stale environment variable. Set SUME_COM_WEBHOOK_SIGNING_SECRET from the dashboard and redeploy. Two equal values clear the secret, so the fault is in your code. After a recent rotation the header already names the new secret; see the rotation overlap.

What should I skip?

Do not paste request bodies carrying live signatures, and do not screenshot the revealed secret. Both values plus the delivery time are enough for support to find the request. The verifier details are in the delivery debugging checklist.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume