Building Reliable Webhooks: The Provider Side

D
Dick Edidiong Bassey
·

SellTrove exposes webhooks to partner integrations for events like order.created, payment.completed, and product.updated. Building the provider side of webhooks teaches you why consumer-side webhook handling discipline matters so much.

The delivery architecture: events are published to an internal queue on occurrence. A webhook delivery worker consumes the queue, retrieves the subscriber endpoints for each event type, and attempts delivery with a 5-second timeout.

The retry strategy: exponential backoff with jitter over 24 hours. After 24 hours of failed delivery, the event is marked as failed and the subscriber is alerted via email. Failed events are stored and available for manual replay.

The signature strategy: every webhook payload is signed with HMAC-SHA256 using the subscriber's secret key. The signature is sent in the X-Webhook-Signature header. Subscribers must verify the signature before processing.

The dashboard: subscribers can view their webhook delivery logs, see which events failed, and trigger manual replays. Observability into webhook delivery is what separates a trustworthy integration platform from an unreliable one.

— Dick Bassey | DevDick | 2025