Webhook signature mismatch: compare the secret fingerprint
Before filing a ticket for a Sume signature mismatch, compare the secret fingerprint header with the dashboard value. It is safe to paste into a ticket.

Open the dashboard before you open a ticket. Match the x-sume-webhook-secret-fingerprint header of the failing request to the value beside your secret, and paste both into the ticket. Those two strings are shareable; the secret is not.
From Job webhooks and Verifying webhooks, read 2026-09-30.
What should the ticket contain?
| Item | Where it comes from |
|---|---|
| Fingerprint from the delivery | The x-sume-webhook-secret-fingerprint header |
| Fingerprint from the dashboard | Webhooks tab, beside the secret |
| Never include | The secret itself |
Why does the vendor world care about this?
Svix's September 2026 changelog describes customers debugging failed deliveries by reading attempts, payloads and responses from their editor without leaving it. The same instinct applies here: support can only help with what you can paste, and a fingerprint is pasteable while the secret is not.
What does a mismatch mean?
Two different values mean the receiver loaded another secret, often a stale environment variable. Set SUME_COM_WEBHOOK_SIGNING_SECRET from the dashboard and redeploy. Two equal values clear the secret, so the fault is in your code. After a recent rotation the header already names the new secret; see the rotation overlap.
What should I skip?
Do not paste request bodies carrying live signatures, and do not screenshot the revealed secret. Both values plus the delivery time are enough for support to find the request. The verifier details are in the delivery debugging checklist.
Sources
Related posts
More in Developers
- What not to log from an AI API: keys, signed URLs, private media
Safe to log: request ids, job ids, status and sanitized media metadata. Unsafe: API keys, signed URLs, raw private media URLs and excess user content.
- webcrypto_modern_algorithms flag: verifying a Sume webhook
Sume's verifyWebhook runs on plain WebCrypto in Workers. The docs list no compatibility flag for it, so webcrypto_modern_algorithms is not a step to add.
- xAI video status done/expired vs Sume completed/failed
xAI's Grok Imagine video status values are pending, done, expired and failed. Sume uses pending, in_progress, completed, failed and cancelled. Port a poll loop.
- Zapier Catch Hook test trigger with Sume Send test
Zapier lists the three most recent webhooks from the past hour. Use Sume's Send test to put a signed webhook.test sample there before a real run exists.
Written by Sume