Webhooks
Push callbacks, signature verification, ordering and at-least-once delivery.
5 to work through
-
advanced
A billing platform must deliver events to thousands of customer endpoints with wildly varying reliability. What guarantees should it offer, and what must it require of consumers?
2 min answer -
advanced
A communications platform delivers webhooks to customer endpoints that are frequently slow, occasionally down, and sometimes process the same event twice. Design the delivery system and state the guarantee you can honestly publish.
2 min answer -
advanced
Design a webhook delivery system for a platform with 10,000 customers. What are the hard parts?
2 min answer -
advanced
Design outbound webhook delivery for a platform with tens of thousands of subscribers whose endpoints have wildly varying reliability. What guarantees can you offer and how do you prevent one bad subscriber from harming the rest?
2 min answer -
advanced
You are building webhook delivery for a platform. What must exist beyond sending an HTTP request?
1 min answer
7 terms in this topic
At-Least-Once Delivery
The delivery guarantee that a message will arrive but may arrive more than once - the strongest practical guarantee across an unreliable boundary, wh…
practiceDelivery Attempt Log
A customer-visible record of every outbound delivery attempt - its response, timing and payload - which converts a support burden into self-service.
patternStable Event Identity
An event identifier that is identical across every delivery attempt of the same event - the single property that makes at-least-once delivery usable,…
case-studyStripe Webhooks: Delivering to Systems You Do Not Control
Outbound event delivery to arbitrary customer endpoints requires signing, retries over days, explicit at-least-once semantics and a replay interface.
practiceWebhook Reliability
The delivery, retry, ordering, verification and replay concerns that separate a production webhook system from a fire-and-forget HTTP POST.
conceptWebhook Retry Policy
The provider's schedule for re-attempting failed deliveries, and the contract the receiver must be built against.
practiceWebhook Signature
An HMAC over the raw request body using a shared secret, letting a receiver verify a webhook genuinely came from the provider.
Neighbouring topics
API & Integration
General material on integrating systems through contracts.
REST Design
Resources, uniform methods, status codes and statelessness.
GraphQL
Client-specified queries, N+1 resolution and query-cost control.
gRPC APIs
Contract-first RPC, generated clients and protobuf compatibility rules.
API Versioning
URL, header and account-pinned versioning, and who carries the burden.
Backward Compatibility
Which changes are safe, and how to make breakage a build failure.
Contract Testing
Verifying what consumers actually rely on, without a shared environment.
API Documentation
OpenAPI as a machine-checked contract rather than as prose.
Rate Limiting
Algorithms, shared counters, and signalling rejection properly.
Idempotency Keys
Client-generated keys stored atomically with the operation they guard.
Pagination & Filtering
Offset versus cursor, stable ordering and unbounded result sets.
API Error Handling
Error shapes, retryability signals and machine-readable causes.
Event-Driven Integration
Publishing facts rather than commands, and versioning event schemas.
Message Formats
JSON, Protobuf, Avro — schema evolution and payload economics.
Schema Registry
Enforcing compatibility on events the way CI enforces it on code.
Integration Patterns
Routers, translators, splitters, aggregators and dead letter channels.
Legacy Integration
Reaching systems that cannot change, without importing their model.
Partner & B2B Integration
External contracts, onboarding, sandboxes and long deprecation windows.
APIs as Products
Ownership, lifecycle, deprecation policy and developer experience.