Webhook
Also called: HTTP callback, event notification, webhook endpoint.
Another service calls a URL on your server when something happens there, like "payment succeeded". You don't have to keep asking; the event comes to you.
When a payment succeeds, Stripe calls your server; your server never asks. If your server is down, Stripe tries again later, waiting longer each time (sped up here). Any 2xx answer counts as delivered: 200 here, 202 in the GitHub prompt.
Tries: 0 · Orders paid: 0 · Your server asked Stripe: 0 times
No payment yet. Your server is waiting; it does not ask Stripe for news.
Say it in a prompt
Receive GitHub push events at POST /webhooks/github. Check the X-Hub-Signature-256 HMAC against our secret, answer 202 within 10 seconds and queue a build job for the pushed branch, and skip any delivery whose X-GitHub-Delivery id we have already handled. Vague vs precise prompt
Vague prompt
let my app know when a Stripe payment goes through Typical resultChecks the Stripe API every minute from a cron job, or accepts any JSON posted to /stripe without checking who sent it. When Stripe sends the same event again, the order is handled twice.
Precise prompt
Add POST /webhooks/stripe: verify the Stripe-Signature header with the endpoint secret using the raw body, reply 200 at once and do the work in a background job, skip event ids already processed, and on payment_intent.succeeded mark the order paid. Typical resultOrders turn paid a few seconds after payment, fake requests get 400, and a resent event never marks an order paid twice.
Seen on
You might describe it as
- the other service calls my server when something happens
- get told when a payment goes through
- a URL that another app sends events to
Not to be confused with
- Polling
A webhook is the other service calling you once when something happens; polling is you asking again and again.