Skip to content
Module
Tech

Webhook

A webhook is an HTTP request that a service sends automatically to a URL you provide when an event happens, such as a payment succeeding or a file being uploaded. Instead of your system asking over and over whether something changed (polling), the other system notifies you. The request carries a payload describing the event, and your endpoint replies with a success status to confirm receipt.

Why it matters for a PM

Webhooks are how many products learn about events they do not control: a subscription renewed with a payment provider, a document signed, a message received. They drive critical states such as access rights after a payment, so their failure modes are product questions: what happens if an event arrives twice, late, out of order, or never?

Example

When a customer pays, the payment provider sends a webhook to the product's server. The server verifies the signature, checks that this event ID has not been processed yet, activates the subscription and returns a success status. If the server is down, the provider retries later.

Key points

  • Senders retry when they do not get a success response, so duplicates are normal.
  • Handlers should be idempotent: processing the same event twice must not change the outcome.
  • Verifying the signature of each request rejects forged events.
  • Answer fast and do heavy work in the background to avoid timeouts.
  • A log of received events helps investigate and replay failures.

Common mistakes

  • Granting access on the redirect after checkout instead of on the confirmed payment event.
  • Assuming events always arrive in order.
  • Exposing a webhook endpoint without signature verification.

Go further with Module

The courses and lessons that cover this concept: