Zapier Catch Hook as a Sume per-item webhook receiver: 10 MB, 200

A Zapier Catch Hook can receive a Sume run webhook. Zapier's own help sets the payload cap and the response, which decide what Sume sees on delivery.

3 min readSume
All posts

Can a Zapier Catch Hook receive Sume run webhooks?

Yes. Sume sends an HTTPS POST to the webhook_url you set on a run, or on each item of a bulk queue, and a Catch Hook URL is a public HTTPS endpoint. Sume requires a public HTTPS URL of up to 2,048 characters and does not follow redirects, so paste the Catch Hook URL as it is.

Zapier's help page on webhook triggers says the maximum payload is 10 MB for triggers and 2 MB for Catch Raw Hook, and that an active Zap returns a 200 (read 2026-10-04). A terminal Sume event is a small JSON envelope, so neither cap matters for it. The page also says you can add silent/ to the URL if your application needs an empty response.

What does Sume see as the response?

Zapier's page says an active Zap returns a 200 and that the response cannot be customized on a standard Catch Hook, so Sume will always get the same plain acknowledgment. If a delivery is missed, for example because the Zap was switched off, POST /v1/format-runs/{id}/webhook/redeliver sends the current terminal receipt again, to the same URL.

Zapier will not verify Sume's signature for you. If you need to check Sume's signature, use Catch Raw Hook so the body is unparsed (its 2 MB cap is still ample), and verify x-sume-webhook-signature in a code step. The header is sume-v1=<hex>, an HMAC-SHA256 of <timestamp>.<raw body> with a 300 second tolerance, and a verifier must refuse an empty secret.

Zapier limits from its help page; Sume limits from the run-webhooks docs, read 2026-10-04.
ItemValueSource
Catch Hook payload cap10 MBZapier help
Catch Raw Hook payload cap2 MBZapier help
Response for an active Zap200Zapier help
Sume webhook URLpublic HTTPS, up to 2,048 characters, no redirectsSume docs

How do I make the Zap safe?

  • Send a test delivery with POST /v1/webhooks/test-deliveries before a real batch.
  • Dedupe on the envelope's request_id, which equals the run id and is stable across retries.
  • Order events by created_at, not request_id.
  • Branch on outcome: ok, degraded or error.

Sources

Related posts

More in Formats

All Formats posts

Written by Sume