webhooks
Installation
SKILL.md
Webhooks — the inbound front door that survives retries and forgeries
You are building the side of a webhook that receives. Some external system pushes an HTTP POST at your endpoint; your job is to prove it is real, refuse to act on it twice, and answer fast. That is the whole mandate.
This skill is provider-agnostic — it teaches the mechanics every webhook source shares, not any one vendor's event catalog — and it ends at "enqueued." What happens to the event afterward is a different job:
- The Stripe-specific scheme (
Stripe-Signature,t=,v1=,stripe listen, the event model) →../stripe/SKILL.md. - Email bounce/complaint webhooks where the point is suppression state →
../email-connector/SKILL.md. - The outbound client that calls someone else's API →
api-connector-builder. - Multi-step orchestration after the event lands →
automation-flows. - Broker/queue tuning (BullMQ concurrency, DLQ ops) →
redis. - Constant-time compare, secret handling, supply-chain hygiene →
../secure-coding/SKILL.md.