Test a video webhook receiver before the first job: Sume vs fal

Sume sends a signed dummy webhook.test with one API call. fal retries real results up to 31 times and treats 3xx as failure, so test your URL first.

4 min readSume
All posts

With Sume you can test a receiver before you spend a credit. POST /v1/webhooks/test-deliveries (key scope account:write) sends a dummy signed webhook.test to the URL you type, or you can use Send test on /dashboard/webhooks. The body has no job_id, so it never touches your job table. Do it once for every new URL, and again after a framework upgrade.

What fal does on failure

The fal webhooks page, read today, says fal retries a failed delivery up to 31 times with increasing backoff until the stored result expires, which is about an hour, or about 6 minutes for results of 10 KB or more. Redirects are not followed, and a 3xx is a permanent failure. The webhook URL goes in the fal_webhook query parameter or webhookUrl.

A redirect from http to https, or from a bare domain to www, is a common cause of a lost fal result. The same redirect is worth removing for Sume, whose URLs must be public HTTPS.

Delivery rules compared, read 2026-10-08
ItemfalSume
AttemptsUp to 31Up to 10
SpacingIncreasing backoffFixed 30 s
Per attempt timeoutNot stated on the page10 s
SignatureED25519, JWKSHMAC-SHA256, sume-v1
Replay window300 s leeway300 s default
Dummy test callNot read on this pagePOST /v1/webhooks/test-deliveries

What the Sume test proves

The test checks four things in one call: that the URL is reachable over HTTPS, that your route returns a 2xx, that the raw body reaches your verifier, and that your secret is the right one. The payload looks like this.

{
  "event": "webhook.test",
  "request_id": "req_wh_test_...",
  "payload": {
    "ok": true,
    "message": "Sume webhook test. Not a job or Format run."
  }
}

Test, then redeliver

Send test and Redeliver are different. Redeliver, POST /v1/jobs/{job_id}/webhook/redeliver (jobs:write), replays the real terminal event with a fresh timestamp and signature, and does not use one of the 10 automatic attempts.

  • Run the test after each deploy that touches the route.
  • If the signature fails, compare x-sume-webhook-secret-fingerprint with the dashboard fingerprint.
  • Return a 2xx after you store the event.

A pre-flight checklist

Run these before you point a real job at a new URL, in this order.

  • Open the URL in a client that follows redirects off, and confirm it answers the POST directly with a 2xx and no 3xx.
  • Send the Sume test and confirm 2xx in under 10 seconds.
  • Break the secret on purpose and confirm that you get 401, then restore it.
  • Send the real event with redeliver and confirm that your dedupe on job_id ignores the second copy.

Why both vendors make this matter

A lost webhook is expensive because the work is already paid for. fal keeps a result for about an hour (about 6 minutes for results of 10 KB or more) and retries until then; Sume keeps the job and its durable media.sume.com URLs and lets you redeliver after the automatic attempts are used up. The Sume test removes the first-delivery risk, and the redeliver call removes the late-recovery risk.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume