AI music API webhook: get a callback when the track is ready
Submit a music job with mode webhook and a public HTTPS URL, verify the signed callback, and keep polling as a backup. Headers, events and retries.

To be called back when a music track is ready, submit to POST /v1/music-router/generate with mode: "webhook" and a public HTTPS webhook_url. Sume sends one signed terminal event, job.completed, job.failed or job.canceled, and no progress events. Keep polling status_url as a backup.
Everything here is from the Webhooks, Music Router and Jobs and results docs, read 2026-09-29.
How do I submit with a webhook?
Webhook URLs must be public HTTPS; localhost, private-network and non-HTTPS URLs are rejected. The submit returns 202 with the job id and polling URLs at once.
curl -X POST https://api.sume.com/v1/music-router/generate \
-H "Authorization: Bearer $SUME_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: music-hook-001" \
-d '{
"prompt": "Gentle acoustic ballad, 70 BPM, G major. A 1-minute track. Instrumental, no vocals.",
"mode": "webhook",
"webhook_url": "https://example.com/hooks/sume"
}'How do I verify the callback?
Sume signs the raw JSON body with HMAC SHA-256 over <timestamp>.<raw_body>. The headers are x-sume-webhook-timestamp and x-sume-webhook-signature: sume-v1=<hex>. During a secret rotation the signature header carries one entry per live secret, so accept the delivery if any sume-v1= entry matches. Reject a timestamp outside your tolerance; the docs suggest five minutes. Read your signing secret from the dashboard Webhooks tab or GET /v1/webhooks/signing-secret, and refuse to verify with an empty secret. The docs give a full TypeScript verifier.
What does delivery guarantee?
| Item | Behavior |
|---|---|
| Events | job.completed, job.failed, job.canceled only |
| Retries | Up to 10 attempts in total |
| Spacing | Fixed delay, 30 s by default |
| Timeout | 10 s per attempt |
| Idempotency | Use job_id as your key |
| Missed events | Redeliver via POST /v1/jobs/{job_id}/webhook/redeliver, or poll |
Where is the audio in the payload?
The completed event carries a payload.artifacts list like the job result: the audio entry has type audio and a media.sume.com URL. Return any 2xx after storing the event durably, then fetch the file.
Sources
Related posts
More in Developers
- AI vendor risk assessment: questions and where to look
An AI vendor risk assessment adds training, model providers and spend to a SaaS review. The questions, and where Sume's public pages answer them.
- API sandbox environment: test a paid API without paying
An API sandbox is a separate test environment with fake or free results. Sume has none, so test with its spec, free checks and spend caps.
- API throttling vs rate limiting: what's the difference?
Rate limiting refuses requests over a quota with a 429; throttling slows or queues the excess instead. What each one means for your client.
- API uptime SLA: what it promises, and Sume's terms
An API uptime SLA promises a monthly availability percentage and credits if missed. Sume's terms offer none; how to build around that.
Written by Sume