Sume webhook_url with :8443 is rejected: HTTPS default port only
Sume rejects any webhook_url with an explicit port such as :8443. Use the default HTTPS port, or poll instead. What the check accepts, and where it runs.

A Sume job webhook_url must be a public HTTPS URL with no explicit port, so https://hooks.example.com:8443/sume is refused with a 400 invalid_request. Put the receiver behind the default HTTPS port, or skip the webhook and poll the job.
This comes from the URL check in the Sume repo (the shared public-URL helper that the API schema and the delivery worker both call), not from a sentence in the docs. The docs say the URL must be public HTTPS; the port rule is the part that surprises people who test with a dev server on 8443 or 3443.
What the check accepts
The helper requires the https scheme, no username or password, no explicit port, and a hostname that is not private. An explicit :443 is accepted only because URL parsing drops the default port before the check sees it.
| webhook_url | Result |
|---|---|
| https://hooks.example.com/sume | Accepted |
| https://hooks.example.com:443/sume | Accepted (443 is normalized away) |
| https://hooks.example.com:8443/sume | Rejected, 400 invalid_request |
| http://hooks.example.com/sume | Rejected, not HTTPS |
| https://user:pw@hooks.example.com/sume | Rejected, credentials in URL |
Where it runs
The check runs twice. The first run is at submit time, where the API schema limits the URL to 2048 characters and answers 400 with the message that webhook_url must be a valid public HTTPS URL. The second run is at delivery time, so a URL that was fine at submit but now resolves somewhere private is still blocked.
Because the first check is at submit, you find out before any credits are reserved for a job that could never notify you. That is the useful side of a strict rule.
What to do instead
If your receiver can only listen on a non-default port, you have three options.
- Put a reverse proxy or load balancer on 443 and forward to your port.
- Use a tunnel that exposes a public HTTPS hostname on 443 while you develop.
- Do not use a webhook: poll GET /v1/jobs/{id} until the job is terminal.
Tradeoffs
A proxy is one more thing to run and secure. Polling costs reads but needs no inbound network at all, which is why it is the better choice behind a strict firewall. Either way, the job itself is not affected by the webhook choice; it runs and bills the same.
Sources
Related posts
More in Developers
- Sume webhook hostname with a private DNS answer is blocked entirely
If any A or AAAA answer for your Sume webhook_url hostname is private, the whole target is blocked. How the resolve-once check works and how to debug it.
- What to log from a Sume MCP agent: ids and status, never signed URLs
Log request ids, job ids when needed, high-level status and sanitized media metadata. Keep API keys, signed URLs, raw private media URLs and transcripts out.
- Which AI video model makes a 25-second clip? Duration check in Python
Only some Sume video models accept 25 seconds in one request. See each model's duration range and filter a target length in a few lines of runnable Python.
- Which Sume audio endpoint do I need? TTS, STT, music, detach, split
Sume has separate endpoints for text to speech, speech to text, music, detaching video audio, and splitting or joining audio. Here is which to call for what.
Written by Sume