Resta saysWebhooks invert the model — the server calls you when an event happens.
Instead of polling "any updates yet?", you register a webhook: a URL the provider POSTs to when an event occurs (payment succeeded, PR merged). Your endpoint receives the event payload in real time. Verify the signature to ensure it's genuine, and respond fast (2xx) — do heavy work asynchronously so you don't time out the sender.
Power-ups you unlock
Provider POSTs to your URL on events
Push, not poll — real-time
Verify the signature for authenticity
Respond 2xx fast; process async
The 401 Bandit attacks — common mistakes
Not verifying the webhook signature
Slow handlers that time out the sender
No retry/idempotency handling for duplicates
Boss battleSketch a webhook receiver that verifies a signature and acks quickly.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>POST /webhooks/stripe
X-Signature: t=...,v1=...
{ "type": "payment.succeeded", ... }
→ verify sig → 200 OK fast → process async</pre></body></html>