WhatsApp webhook media IDs expire in 7 days: download and store
WhatsApp webhook media IDs expire after 7 days and media URLs after 5 minutes. Download inbound media promptly, then import it into Sume to edit it.

Media you receive through a WhatsApp Cloud API webhook has a media ID that expires after 7 days, and the media URL you resolve from it expires after 5 minutes. So retrieve the URL and download the bytes as soon as the webhook arrives, then keep your own copy. To edit it with Sume, import the stored file with the media-imports endpoint.
How do the expiry windows differ?
Meta's media reference distinguishes uploads you make from media you receive. Uploads made through the API persist for 30 days, as another post covers. Inbound media IDs in webhooks last 7 days, and every media URL expires after 5 minutes.
| Item | Lifetime |
|---|---|
| Media uploaded via API | 30 days |
| Media ID in a webhook | 7 days |
| Media URL | 5 minutes |
What should the webhook handler do?
- Acknowledge the webhook quickly.
- Resolve the media ID to a URL and download at once, with your access token.
- Store the bytes under your own key.
- Process later from your copy, never from the WhatsApp URL.
How do I bring the file into Sume?
Sume tools read only Sume-hosted media, so import first: POST /v1/media-imports is the documented import step. Once the import returns a Sume-hosted URL, call the trim, filter or frames tools on that URL. The tool pages in the docs link to the import step; check them for accepted sources and the exact body, which this post does not repeat.
What should I verify?
Meta can change lifetimes, so read the media reference at integration time. The API reference covers authentication on the Sume side.
Sources
Related posts
More in Integrations
- Windmill webhook token in the URL: calling it from a Sume job
Windmill prefers a bearer header, but Sume's webhook_url is just a URL, so the token must ride in the query string. How to scope it and still trust the result.
- X API made_with_ai: disclose AI media when you create a post
The X API v2 create-post body has a made_with_ai boolean to disclose AI-generated media. Where it sits, what it needs, and how to prep the clip with Sume first.
- X API media metadata: alt text up to 1000 characters for AI images
X's media metadata endpoint takes alt_text.text up to 1000 characters. Write alt text for generated images and size the image with the Sume images API first.
- X media upload total_bytes ceiling of 16 GiB: trim long AI video first
X's media upload init accepts total_bytes up to 17179869184 (16 GiB). Why the cap rarely binds for AI clips, and how Sume video-trim keeps uploads short.
Written by Sume