Backend · core

Webhooks

Outbound event delivery: signing, retries, idempotent receivers.

backendwebhooks

Mental model

A webhook is the provider calling your server when something happens, instead of your server polling them. Three rules: verify the signature so you trust the sender, return 200 fast and queue the actual work, and assume the same event may be delivered more than once.

How to study Webhooks

Begin by restating the mental model in your own words, then connect it to a concrete system you have built or operated. Name the mechanism, the constraint it addresses, and the trade-off it introduces. Use Stripe — Webhooks to check details, but close the source before writing your explanation. Retrieval is the learning step; rereading is only preparation.

Next, compare Webhooks with Idempotency. Ask what changes in correctness, latency, resource use, operability, and failure recovery. Complete Verify webhook HMAC and preserve the command, input, output, and one failed attempt as evidence. Finish by explaining the idea without jargon to someone who has not studied the track.

Proof of understanding

  • Explain the mechanism from first principles and identify the state it reads or changes.
  • Give one situation where the concept is the right choice and one where it is not.
  • Predict a realistic failure mode before running the drill, then compare the prediction with evidence.
  • Connect the result to a roadmap or build artifact instead of treating the concept as isolated trivia.

Learn from primary sources

Practice and explain it back

Verify webhook HMAC

Body b, secret s, header HMAC-SHA256(s,b). Constant-time compare. Why reject if timestamp >5m old?

Expected evidence: Prevents replay; timing-safe compare prevents forgery leaks.

Open the interactive drill →

Review prompts

  • Why must a webhook receiver return 200 before doing the work, and what does that force on you?

Build evidence

Use a roadmap capstone to turn this concept into working evidence.

Prerequisites

Related concepts

Learning paths

None assigned yet.