Skip to main content
Webhooks are at-least-once notifications. Your consumer must authenticate, acknowledge quickly, and deduplicate by event ID before applying business changes.

Common envelope

Treat id, event, and timestamp as envelope metadata. The data shape is event-specific and must be validated against the event documented for your integration.

Consumer flow

Do not parse and mutate business state before signature verification. Do not perform long-running work before acknowledging the delivery.

Delivery behavior

Non-2xx responses and timeouts can be retried. A duplicate delivery is not necessarily a duplicate event. Persist the event ID and handler result so retries are safe. See Webhooks for endpoint registration, secret rotation, test deliveries, and the current event catalog.