Receive a webhook safely
A public URL that strangers can POST to.
I need to receive webhooks from <provider> at <path>. Implement the endpoint with all of this: - Verify the signature before trusting a single byte. Show me how. - Respond 200 fast, then do the work in the background — providers time out and retry. - Make it idempotent: the same event delivered twice must not charge, email or create anything twice. - Log every event received, including ones I reject. What does the provider do if I return a 500? Design for that.
Providers retry. Yours will receive duplicates whether you handle them or not — the only choice is whether that's a feature or a support ticket.