Google Cloud Workflows callback needs an IAM token: relay Sume

A Cloud Workflows callback URL needs the workflows.callbacks.send permission and a Bearer token. Sume webhooks cannot carry one, so relay after verifying.

4 min readSume
All posts

Do not register the Cloud Workflows callback URL as the Sume webhook_url. Google's page says the caller needs the workflows.callbacks.send IAM permission and sends an Authorization: Bearer token, and the Sume docs document no custom headers on delivery, so a verified relay should make the callback.

Sume facts are from the Webhooks docs; the Google text was read 2026-09-30.

What does a callback require?

Google says the callback URL can be used to trigger the callback from a process external to the workflow, that the default method is POST, and that callers need workflows.callbacks.send. The await_callback timeout default is 43200 seconds, which is 12 hours.

Callback constraints against Sume delivery, read 2026-09-30. Sume: Webhooks.
TopicGoogle callbackSume delivery
AuthBearer token with IAM permissionsume-v1 HMAC signature headers
MethodPOST by defaultPOST to a public HTTPS URL
Wait ceiling43200 seconds by defaultUp to 10 attempts on failure

What does the relay send?

After it verifies the signature, the relay posts to the stored callback URL with a token for a service account that has the permission. This shell form shows the request; build the token however your platform does.

curl -X POST "$CALLBACK_URL" \
  -H "Authorization: Bearer $(gcloud auth print-access-token)" \
  -H "Content-Type: application/json" \
  -d '{"job_id":"job_123","event":"job.completed"}'

Where does the callback URL come from?

Keep the callback URL your workflow is waiting on, and store it against the Sume job id when you submit. When job.completed arrives, look the URL up by job_id, which is the idempotency key for job events.

What if the workflow times out first?

The Sume job is unaffected; a timeout on your side does not cancel it. Read the result with the job id afterwards and never resubmit the paid request.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume