GITHUB_TOKEN can't redeliver webhooks; Sume uses jobs:write

GitHub's built-in GITHUB_TOKEN cannot redeliver webhooks. For Sume job webhooks, a jobs:write API key calls POST /v1/jobs/{job_id}/webhook/redeliver instead.

4 min readSume
All posts

GitHub's guide says the built-in GITHUB_TOKEN does not have sufficient permissions to redeliver webhooks and recommends a personal access token. Sume has no such limit to work around: POST /v1/jobs/{job_id}/webhook/redeliver needs only an API key with jobs:write, so a workflow can run it with a stored secret.

What does Sume redeliver do?

It re-POSTs that job's real terminal event (job.completed, job.failed or job.canceled) with a fresh timestamp and signature. It still works after automatic attempts are exhausted and does not consume one of the automatic 10. It does not change the destination URL; a new URL is a new job. Read 2026-10-01 in Job webhooks.

Redeliver versus Send test in the Sume docs, read 2026-10-01.
ActionEndpointWhat it sends
RedeliverPOST /v1/jobs/{job_id}/webhook/redeliver (jobs:write)The job's real terminal event, fresh signature
Send testPOST /v1/webhooks/test-deliveries (account:write)A dummy signed webhook.test payload

How do I know a delivery needs redelivery?

Delivery status is visible on the job object and in job events when available. The status values are pending, delivering, delivered, retrying, failed and exhausted. Automatic delivery makes up to 10 attempts total, with a fixed delay between attempts, 30s by default. Redeliver when the status is failed or exhausted.

What can go wrong?

The API returns 409 if the job is still running or was created without a webhook_url, and 404 for a job you cannot see. Your receiver must treat job_id as the idempotency key, because a redelivered event can arrive after one it already handled. For a step-by-step check, see debug a Sume webhook delivery.

Which key should the workflow hold?

Give the workflow a Sume API key scoped for jobs:write and keep it in your CI secret store. Keep status_url polling available too, since delivery is an optimization and never the only recovery path.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume