EventBridge API destinations: call a paid API without Lambda

An EventBridge API destination calls an HTTPS API straight from a rule, with a 5-second timeout and retries on 409, 429 and 5xx. Key every call.

5 min readSume
All posts

An EventBridge API destination is an HTTPS endpoint that a rule or pipe calls directly as its target, so you can call an external API with no Lambda in between. A connection holds the credentials (EventBridge stores them in AWS Secrets Manager), and an optional invocation rate limit caps calls per second. Each call must answer within 5 seconds, and EventBridge retries 401, 407, 409, 429 and 5xx responses.

The AWS facts come from AWS's API destinations, connections, authorization methods, create an API destination and input transformation pages. The Sume facts come from Create a run and Authentication. All were read on 2026-09-29. Sume has no official EventBridge connector; this is a plain HTTPS call.

Does a slow API work behind a 5-second timeout?

Only if its create call answers before the work is done. AWS says a request that takes longer than 5 seconds times out and is retried under your retry policy, which by default on an event bus is 24 hours and 185 attempts. A media API that holds the connection until a video renders will time out, and each retry can start the job again.

A Sume Format run fits the pattern: POST /v1/formats/{handle}/{slug}/runs answers 202 Accepted with a run receipt, and the result arrives later on a webhook or by polling. Sume's docs don't state how long the create itself takes, so a timeout is still possible; the idempotency key below makes its retry safe. A Format run's communication.mode is async or webhook, and neither blocks. Don't put a Sume job submit in sync mode behind an API destination: it can hold the request for up to 30 seconds.

How do I set up the connection and destination?

Three pieces: a connection for the credential, the API destination for the endpoint, and the rule that sends matching events to it.

  • Connection: choose API Key authorization and enter the key name x-api-key with your Sume key as the value. Sume accepts Authorization: Bearer or x-api-key, and a request carrying both is refused with 401.
  • API destination: endpoint https://api.sume.com/v1/formats/acme/product-promo/runs, method POST. The URL must use HTTPS, and the connection must reach the AUTHORIZED state first.
  • Invocation rate limit per second: size it to your write budget. Sume's Free plan allows 120 writes a minute, which is 2 a second; Pro allows 300.
  • Rule target: the API destination, with an input transformer that builds the request body from the event.
Input path:
{ "order": "$.detail.order-id", "product": "$.detail.product-url" }

Input template:
{
  "idempotency_key": "order-<order>-promo-v1",
  "instruction": "15-second vertical promo",
  "input": { "product_url": "<product>" },
  "generation_spend_cap_usd": 20
}

How do I stop EventBridge retries from paying twice?

Put the idempotency key in the body, built from the event's business data. Sume's run create accepts idempotency_key as the body spelling of the Idempotency-Key header. A retry of the same event sends the same key and body, and Sume answers 200 with the original run: no second run, no second charge. Don't build the key from the event time; the docs say to derive it from the thing being made.

Also send generation_spend_cap_usd. It caps what one run may spend on generation, up to the platform maximum of $500.

Which Sume errors will EventBridge retry?

EventBridge retries 401, 407, 409, 429 and 5xx, honors Retry-After, and does not retry other 4xx codes. Events that exhaust retries go to a dead-letter queue if you set one; otherwise they are dropped.

From AWS's API destinations page and Sume's Create a run page, read 2026-09-29.
Sume responseMeaningEventBridge
202 / 200Fresh run / replay of the same keyDelivered
401 unauthorizedMissing, revoked, or doubled keyRetried until the policy runs out
402 insufficient_creditsThe workspace can't fund the runNot retried
409 idempotency_key_in_useA concurrent duplicateRetried; the retry receives the original run
409 idempotency_conflictSame key, different body; nothing runsRetried, and fails the same way
429 rate_limitedWrite budget spentRetried after retry-after
503 studio_agent_upstream_unavailableSume-side outageRetried; Sume says retry with the same key

What does this not do?

An API destination starts the work; it doesn't follow it.

  • It doesn't deliver the result. Set communication.webhook_url on the body to an HTTPS endpoint you run, or poll the run.
  • It doesn't fix a revoked key. Update the connection with a new key; until then each event keeps retrying on 401.
  • For a schedule instead of an event, Run a Lambda function on a schedule with EventBridge covers EventBridge Scheduler.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume