WhatsApp Cloud API media ID expiry: 30 days, URL 5 minutes
WhatsApp media IDs from the API expire after 30 days, webhook IDs after 7, and a media URL works for 5 minutes. Keep your own durable source, not the ID.

A WhatsApp Cloud API media ID returned by the API expires after 30 days, an ID received in a webhook after 7 days, and the media URL you get from an ID is valid for 5 minutes. Treat the ID as a short-lived handle, and keep the original file at a URL you control, for example a Sume media.sume.com artifact.
Numbers are from Meta's media reference, read 2026-10-01; Sume artifact behavior from its Image generation docs.
What are the WhatsApp expiry windows?
| Item | Lifetime |
|---|---|
| Media ID returned by the API | 30 days |
| Media ID in a webhook | 7 days |
| Uploaded files | Persist 30 days unless deleted earlier |
| Media URL from an ID | 5 minutes |
Why not store the media ID?
Because it stops working. After 30 days (7 for webhook IDs) you must upload the file again, which requires that you still have it. And the URL for downloading an inbound file is only valid for 5 minutes, so fetch it right away and save the bytes.
What should be the durable source?
The Sume docs for image generation show results as public HTTPS URLs on media.sume.com, and the Sume docs describe results as media.sume.com artifacts. Those pages do not give a retention period, so confirm that against your own needs. Store that URL with your message record, and on each send upload from it to WhatsApp for a fresh ID.
What should I do next?
Keep three values per message: source URL, WhatsApp media ID, and upload time. If the ID is older than your safe window, upload again. Format and size limits for audio are in WhatsApp audio message formats.
Sources
Related posts
More in Developers
- Which MCP server lets Claude Code or Cursor generate video and images?
MCP servers that let Claude Code and Cursor make video and images: Sume, fal, Replicate, Runway, Higgsfield. Endpoints, sign-in, billing, setup.
- Idempotency keys for AI video APIs: retry without paying twice
An idempotency key makes a retried create return the original run or job instead of a second paid one. How Sume's Idempotency-Key works on each API.
- Signed webhooks for Sume video runs: events, retries, verification
Sume sends one HMAC-SHA256 signed POST when a Format, Action, or Agent Completion run completes or fails. Verify the raw body and dedupe on request_id.
- Spend caps for unattended AI agents: how Sume bounds each run
An unattended agent has no one to approve spend, so Sume caps generation per run: required on Agent Completions, and up to $500 on Format runs.
Written by Sume