WhatsApp Business Tools MCP sets callback URLs: verify your receiver

The MCP can configure callback URLs and field subscriptions. Give it a public HTTPS receiver, and apply the same rule to the webhook_url you send Sume.

5 min readSume
All posts

Meta's WhatsApp Business Tools MCP can configure callback URLs and field subscriptions for you. Point it at a receiver you control and have tested, then reuse the same discipline for Sume: webhook URLs must be public HTTPS, and every delivery must pass signature verification before you act on it.

Meta says the MCP is built for development and testing workflows, so treat the callback it configures as a test endpoint until your production receiver is ready.

What do both webhook systems expect?

Meta describes the setup path; Sume's rules are in its webhook docs.

Callback handling on each side (read 2026-10-05)
QuestionWhatsApp Business Tools MCP (Meta)Sume job webhooks
Who sets the URL?The agent can configure callback URLs and field subscriptionsYou send webhook_url (alias callback_url) on the job submit
URL rulesNot stated in the post readPublic HTTPS only; localhost, private-network and non-HTTPS URLs are rejected
IntegrityNot stated in the post readHMAC-SHA256 sume-v1 signature over <timestamp>.<raw_body>
BackupNot stated in the post readPoll status_url; redeliver with POST /v1/jobs/{job_id}/webhook/redeliver

How do I submit a Sume job that calls my receiver?

Send callback_url on the submit, and use one receiver for both vendors only if it routes on the event type or path. The sample submits a render with a callback and a stable key.

import os
import requests


def submit(prompt: str, key: str, callback_url: str) -> str:
    r = requests.post(
        "https://api.sume.com/v1/videos",
        headers={
            "Authorization": f"Bearer {os.environ['SUME_API_KEY']}",
            "Idempotency-Key": key,
        },
        json={
            "model": "sume/auto",
            "prompt": prompt,
            "aspect_ratio": "9:16",
            "duration": 8,
            "callback_url": callback_url,
        },
        timeout=30,
    )
    r.raise_for_status()
    return r.json()["id"]


if __name__ == "__main__":
    print(submit("A product close-up on a desk", "campaign-42-clip-1", "https://hooks.example.com/sume"))

Test before you trust it

Use Sume's Send test (POST /v1/webhooks/test-deliveries) to confirm that your receiver accepts a signed dummy webhook.test event. Send test never replays a real job; redeliver does.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume