How a webhook works

A webhook inverts the usual request–response pattern: instead of the recipient asking the source,
the source notifies the recipient.

An event at the source (a new order)
        ↓
POST https://receiver.example/webhooks/orders
Content-Type: application/json
X-Signature: sha256=abc123...

{
  "event": "order.created",
  "order_id": "12345",
  "user_id": "u_789",
  "total": 49.90,
  "timestamp": "2025-03-15T14:30:00Z"
}
        ↓
Recipient → HTTP 200 OK → processing on a queue

The recipient has to return 200 quickly, without blocking on business logic. Heavy processing goes
onto an asynchronous queue.

Webhooks against polling

Property Webhook Polling
Delay Milliseconds Up to one polling interval
Load on the source Minimal N requests a second regardless of events
Work for the recipient A public endpoint A scheduler plus the request
Reliability Needs retry logic Easier to guarantee

For real-time events — order sync, price updates, user actions — webhooks are preferable. Polling is
justified when the source does not support webhooks, or when events need to be aggregated in
batches.

Reliability and idempotency

A webhook endpoint has to be idempotent: the same event can be delivered twice, for example on a
retry after a timeout. Processing logic must not create duplicate records on a repeat delivery.

The standard defence against duplicates is to store processed event IDs in a cache such as Redis or
Memcached, with a TTL equal to the source’s maximum retry window.

Important: verify the HMAC signature before you process the request body. It is the only
reliable way to know the webhook came from a trusted source rather than from an unrelated request
to your public URL.

Webhooks in e-commerce integrations

In e-commerce, webhooks are used most often for:

  • Catalogue sync: the personalization platform is notified about price and stock changes from
    the ERP or PIM immediately
  • Order events: the payment system notifies the CRM and the CDP about a new order so the
    customer profile can be updated
  • Behavioural events: the mobile app sends events into the personalization platform so the
    affinity profile stays current in real time