Glossary · Software Architecture

What is Webhook?

Short answer

A webhook is an HTTP request that one system sends to a URL you provide when an event happens, for example a payment succeeding or a form being submitted. Instead of your application repeatedly asking “anything new?” (polling), the other service pushes the news to you as it happens. Stripe, GitHub and Shopify all use webhooks.

How it works

  1. You register an endpoint, such as https://example.com/webhooks/stripe, and choose the events you want.
  2. When an event happens, the provider POSTs a JSON payload describing it to your URL.
  3. Your endpoint verifies the request, records it and responds quickly with a 2xx status.
  4. If you don’t respond in time, the provider retries, often for hours or days.

Receiving webhooks safely

  • Verify the signature: providers sign each request, usually an HMAC of the body with a shared secret. Reject anything that doesn’t match, and check the timestamp to block replays.
  • Respond fast, work later: store the event and process it in a queue job, so slow work doesn’t cause timeouts and retries.
  • Expect duplicates and disorder: make processing idempotent using the event ID, and don’t assume events arrive in order.
  • Reconcile: webhooks can be missed, so periodically check important state through the provider’s API.

In PHP

Laravel Cashier handles Stripe webhooks, and the spatie/laravel-webhook-client package provides signature checks, storage and queued processing for any provider.

Published · Updated · By · All terms

Go deeper