Receiving notifications.
WHAT A WEBHOOK IS
An external service sending a request to your application when something happens.
WHAT TO ALWAYS DO
Verify it genuinely came from the service.
HOW
Check the signature the service provides, using your shared secret.
WHY
Otherwise anyone can send a request claiming a payment succeeded.
THAT IS A REAL AND COMMON ATTACK
WHAT TO EXCLUDE
Webhook routes from request protection, which does not apply to them.
WHAT TO REPLACE IT WITH
Signature verification. Never nothing.
WHAT TO DO ON RECEIPT
Verify Record that it arrived Respond quickly with success Process the work in a queue
WHY RESPOND QUICKLY
Services time out and retry, producing duplicates.
WHAT TO HANDLE
Duplicates, since services retry.
HOW
Record an identifier and ignore anything already processed.
WHAT TO NEVER DO
Trust amounts or statuses in the request without verifying against the service.
WHAT TO LOG
Every webhook received and its outcome.