What is a webhook?
How Stripe tells your app a payment went through. Simple to receive, and easy to get subtly wrong.
In short
A webhook is an HTTP request that one service sends to a URL in your app when something happens on its side, such as a payment succeeding or an email bouncing. Instead of your app asking repeatedly whether anything changed, the other service tells it. Stripe, Clerk and email providers all use webhooks to report events.
Also called: HTTP callback, Event notification
Why it matters when your prototype goes to production
A webhook handler usually works in a demo, because the demo sends each event once, in order, while the server is up. Production breaks all three assumptions. Stripe's documentation says endpoints might occasionally receive the same event more than once, that delivery order is not guaranteed, and that in live mode it retries failed deliveries for up to three days.
What a production webhook handler does
- Verifies the signature, so nobody else can fake an event.
- Records the event id and ignores one it has already processed.
- Answers quickly and does slow work in a background job.
- Stores failures rather than dropping them, and alerts someone.
On Inkwave every Stripe webhook is signature-checked, and failed payments are stored, not logged and dropped. A missing webhook is a missing payment nobody notices.
Common questions
What is the difference between a webhook and an API?
With an API your app asks for data when it wants it. With a webhook the other service sends data to your app when an event happens.
Are webhooks reliable?
They are retried, not guaranteed. A handler has to cope with duplicates, events out of order and deliveries that arrive late.
Related terms
Read next
Sources
More on this: Production architecture & security · All glossary terms
Built something in Lovable you want people to rely on?
We are the engineers who take it the rest of the way — secured, tested, released and supported.