Google Cloud Workflows callback needs an IAM token: relay Sume
A Cloud Workflows callback URL needs the workflows.callbacks.send permission and a Bearer token. Sume webhooks cannot carry one, so relay after verifying.

Do not register the Cloud Workflows callback URL as the Sume webhook_url. Google's page says the caller needs the workflows.callbacks.send IAM permission and sends an Authorization: Bearer token, and the Sume docs document no custom headers on delivery, so a verified relay should make the callback.
Sume facts are from the Webhooks docs; the Google text was read 2026-09-30.
What does a callback require?
Google says the callback URL can be used to trigger the callback from a process external to the workflow, that the default method is POST, and that callers need workflows.callbacks.send. The await_callback timeout default is 43200 seconds, which is 12 hours.
| Topic | Google callback | Sume delivery |
|---|---|---|
| Auth | Bearer token with IAM permission | sume-v1 HMAC signature headers |
| Method | POST by default | POST to a public HTTPS URL |
| Wait ceiling | 43200 seconds by default | Up to 10 attempts on failure |
What does the relay send?
After it verifies the signature, the relay posts to the stored callback URL with a token for a service account that has the permission. This shell form shows the request; build the token however your platform does.
curl -X POST "$CALLBACK_URL" \
-H "Authorization: Bearer $(gcloud auth print-access-token)" \
-H "Content-Type: application/json" \
-d '{"job_id":"job_123","event":"job.completed"}'Where does the callback URL come from?
Keep the callback URL your workflow is waiting on, and store it against the Sume job id when you submit. When job.completed arrives, look the URL up by job_id, which is the idempotency key for job events.
What if the workflow times out first?
The Sume job is unaffected; a timeout on your side does not cancel it. Read the result with the job id afterwards and never resubmit the paid request.
Sources
Related posts
More in Developers
- google/veo-3.1 style ids vs Sume: bare video model ids
OpenRouter names video models org/slug, such as google/veo-3.1. Sume uses bare catalog ids like seedance-2 and never a provider prefix. How to port an id.
- gpt-4o-transcribe-diarize retiring: Sume STT has no speaker labels
OpenAI lists gpt-4o-transcribe-diarize for removal on Feb 26, 2027. Sume STT returns words and sentences with timings, but no speaker field.
- gpt-image-1.5 deprecation: Dec 1, 2026 and Sume model ids
OpenAI removes gpt-image-1.5 and gpt-image-1-mini from its API on Dec 1, 2026. On Sume, send openai/gpt-image-2.5 and list ids with GET /v1/images/models.
- gpt-image-1 shuts down Oct 23, 2026: what to send on Sume
OpenAI lists gpt-image-1 as shutting down October 23, 2026. On Sume, call POST /v1/images with openai/gpt-image-2.5 or sunburst, or sume/auto. Migration steps.
Written by Sume