webhook-reliability
Installation
SKILL.md
Webhook Reliability
Overview
Webhooks fail silently by nature — there's no user staring at a spinner when one drops, so the failure mode is "data quietly went stale" discovered days later. This skill covers both directions: inbound (Stripe, GitHub sending events to us) and outbound (if your product emits webhooks to third parties or customers). The core disciplines — verify, dedupe, retry, record dead letters, monitor — apply to both.
Inbound webhooks
- Signature verification is mandatory, always, first line of the handler — never process a payload before verifying it came from the claimed sender:
// Stripe const rawBody = await req.text(); const event = stripe.webhooks.constructEvent(rawBody, req.headers.get('stripe-signature')!, process.env.STRIPE_WEBHOOK_SECRET!);