WhatsApp Business Tools MCP sets callback URLs: verify your receiver
The MCP can configure callback URLs and field subscriptions. Give it a public HTTPS receiver, and apply the same rule to the webhook_url you send Sume.

Meta's WhatsApp Business Tools MCP can configure callback URLs and field subscriptions for you. Point it at a receiver you control and have tested, then reuse the same discipline for Sume: webhook URLs must be public HTTPS, and every delivery must pass signature verification before you act on it.
Meta says the MCP is built for development and testing workflows, so treat the callback it configures as a test endpoint until your production receiver is ready.
What do both webhook systems expect?
Meta describes the setup path; Sume's rules are in its webhook docs.
| Question | WhatsApp Business Tools MCP (Meta) | Sume job webhooks |
|---|---|---|
| Who sets the URL? | The agent can configure callback URLs and field subscriptions | You send webhook_url (alias callback_url) on the job submit |
| URL rules | Not stated in the post read | Public HTTPS only; localhost, private-network and non-HTTPS URLs are rejected |
| Integrity | Not stated in the post read | HMAC-SHA256 sume-v1 signature over <timestamp>.<raw_body> |
| Backup | Not stated in the post read | Poll status_url; redeliver with POST /v1/jobs/{job_id}/webhook/redeliver |
How do I submit a Sume job that calls my receiver?
Send callback_url on the submit, and use one receiver for both vendors only if it routes on the event type or path. The sample submits a render with a callback and a stable key.
import os
import requests
def submit(prompt: str, key: str, callback_url: str) -> str:
r = requests.post(
"https://api.sume.com/v1/videos",
headers={
"Authorization": f"Bearer {os.environ['SUME_API_KEY']}",
"Idempotency-Key": key,
},
json={
"model": "sume/auto",
"prompt": prompt,
"aspect_ratio": "9:16",
"duration": 8,
"callback_url": callback_url,
},
timeout=30,
)
r.raise_for_status()
return r.json()["id"]
if __name__ == "__main__":
print(submit("A product close-up on a desk", "campaign-42-clip-1", "https://hooks.example.com/sume"))Test before you trust it
Use Sume's Send test (POST /v1/webhooks/test-deliveries) to confirm that your receiver accepts a signed dummy webhook.test event. Send test never replays a real job; redeliver does.
Sources
Related posts
More in Developers
- WhatsApp Business Tools MCP: for dev and testing, not production sends
Meta says the WhatsApp Business Tools MCP is for development and testing, not production sending at scale. Use it to set up; send from your code.
- Which API key scopes does a Sume webhook receiver need?
Verifying a Sume webhook needs no API key at all. Reading the secret, rotating it, sending a test and redelivering a job each need a different scope.
- Which fields to keep from a Sume submit response
Keep the job id, status_url, result_url, events_url, cancel_url, the sync flags and next_poll_after_seconds. Use generation_limits for pacing only.
- Which login is my agent using? mcp_health auth_source on Sume MCP
Call mcp_health on the hosted Sume server to see the auth source of your session, then tools_list and account_me. Read-only OAuth and API-key sessions differ.
Written by Sume