Supabase Edge Function secrets: 100 per project, 2 for Sume

Supabase allows 100 secrets per project. A Sume webhook receiver needs two: your API key and the webhook signing secret. Names, rules and what to verify.

4 min readSume
All posts

Two secrets is all a Sume webhook receiver needs, so it barely touches Supabase's limit of 100 secrets per project: your Sume API key, and the webhook signing secret, which Sume documents under the name SUME_COM_WEBHOOK_SIGNING_SECRET.

Limits are from Supabase's Edge Functions limits page and Sume behavior from Job webhooks, both read 2026-10-01. See also a Supabase Edge Function video webhook.

What are the Supabase secret limits?

The page lists a maximum of 100 secrets per project and a maximum secret size of 48 KiB. It also lists a wall clock limit of 150s on Free and 400s on Paid, which is why a video job should finish by webhook, not by an open request.

Supabase Edge Functions limits as written on the page, read 2026-10-01.
LimitValue on the page
Secrets per project100
Secret size48 KiB
Wall clock (Free / Paid)150s / 400s
Request idle timeout150s

Which two secrets does a Sume receiver need?

The signing secret is read on the Webhooks tab of the dashboard or from GET /v1/webhooks/signing-secret with an API key carrying account:read. Store it as SUME_COM_WEBHOOK_SIGNING_SECRET, the same name the delivery worker signs with. The second is your Sume API key, used to submit jobs and to read status_url as a fallback.

Job webhooks and run webhooks share that one secret, so a single verifier covers both.

What must the function verify?

Sume signs HMAC SHA 256 over <timestamp>.<raw_body>. The SDK page says to pass the raw body: a parsed and reserialized object does not verify. In an Edge Function that means reading await request.text() before anything else. Reject callbacks when the timestamp is outside your replay window; the docs suggest five minutes.

Headers are x-sume-webhook-timestamp and x-sume-webhook-signature. During a secret rotation the signature header carries one sume-v1= entry per live secret, so accept the delivery if any entry matches.

What if the secret is missing or wrong?

Refuse to run with an empty secret. If a signature does not verify, compare x-sume-webhook-secret-fingerprint on the delivery with the fingerprint shown beside the secret in the dashboard, so neither side sends the secret itself. Return a 2xx only after storing the event, and use job_id as your idempotency key.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume