Airtable has no webhook signature check: verify Sume first
Airtable's When webhook received trigger cannot verify signatures and caps payloads at 100kb. Verify the Sume signature in a relay and forward a small object.

Put a small relay between Sume and Airtable: verify the sume-v1 signature there, then forward a compact JSON object to the Airtable webhook URL. Airtable's page says it does not support signature verification for webhooks, so a Sume delivery sent straight to it cannot be authenticated by Airtable.
Sume facts are from the Verifying webhooks docs; the Airtable limits were read 2026-09-30.
What does the Airtable trigger accept?
Airtable lists a payload limit of 100kb per request, five requests per second, POST only, and a JSON body with an object at the top level.
| Topic | Airtable trigger | Sume delivery |
|---|---|---|
| Signature | Not verified | sume-v1 HMAC-SHA256 header |
| Payload size | 100kb | payload: null above 1 MiB |
| Rate | 5 requests per second | Up to 10 attempts on failure |
What does the relay do?
It refuses an empty secret, verifies the raw body, and forwards only what the automation needs. Fetch the full result from result_url later instead of copying a large payload.
import { verifyWebhook } from "@sume-com/sdk";
export default {
async fetch(request: Request, env: Record<string, string>) {
const secret = env.SUME_COM_WEBHOOK_SIGNING_SECRET;
if (!secret || !env.AIRTABLE_HOOK_URL) {
return new Response("not configured", { status: 500 });
}
const body = await request.text();
const ok = await verifyWebhook({ body, headers: request.headers, secret });
if (!ok) return new Response("bad signature", { status: 401 });
const event = JSON.parse(body);
const slim = { event: event.event, request_id: event.request_id };
const res = await fetch(env.AIRTABLE_HOOK_URL, {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify(slim),
});
return new Response(null, { status: res.ok ? 204 : 502 });
},
};Why return 502 on a failed forward?
A non-2xx makes Sume retry, up to 10 attempts. A 204 after a failed forward would silently drop the event.
What about the five-per-second cap?
A busy bulk queue can finish several items close together. Airtable does not say what it does past the cap, so keep a poll of the queue as a backup and dedupe on request_id.
Sources
Related posts
More in Developers
- Anthropic x-api-key is now a fallback: Sume accepts one header
Anthropic's docs list Authorization: Bearer first and call x-api-key a legacy fallback. Sume accepts either, but rejects a request that sends both with a 401.
- AI Act Article 50 in force: what to log per generated file
Article 50 applies from 2 August 2026. Keep a per-file record of job id, request id and artifact URL from Sume, and know what the docs leave unsaid on marking.
- AI Act Article 50 and standard editing: which Sume tools use no model
The Commission's FAQ exempts assistive standard editing from AI marking. Sume's trim, filter, audio detach and timeline docs call themselves ffmpeg-only.
- Speaker diarization API: confidence scores, and what Sume STT returns
AssemblyAI added speaker_confidence (0 to 1) per word and utterance. Sume STT returns word start and end times only, with no speaker or confidence data.
Written by Sume