Skip to main content

Webhook

Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/webhook

In short

A webhook is an automated HTTP request that one application sends to a URL you provide as soon as a specific event happens, such as a completed payment.

What is a webhook?

A webhook lets one system notify another the moment something happens. You register a URL with a service, and when a chosen event occurs, such as a new order, a failed payment, or a push to a code repository, the service sends an HTTP POST request to that URL with details about the event, usually in JSON format.

Webhooks are the opposite of polling. With polling, your app repeatedly asks an API whether anything has changed, which wastes requests and adds delay. With a webhook, the other service pushes the information to you only when there is something new, which is why webhooks are sometimes called reverse APIs.

An everyday analogy is the difference between refreshing a package-tracking page every few minutes and getting a text message when the package arrives. Webhooks are widely used by payment providers, chat tools, Git hosting services, and CI/CD pipelines to trigger automated work.

Because a webhook URL is publicly reachable, the receiver should verify each request, typically by checking a signature computed with a shared secret. Receivers should also respond quickly with a 2xx status code and handle duplicate deliveries safely, since most senders retry when a delivery fails.

At a glance

A shop registers its URL with a payment service once. Later, when a customer pays, the payment service sends an HTTP POST with a payment.succeeded event to that URL, and the shop answers 200 OK. The shop never has to ask whether the payment went through.Your appPayment serviceRegister https://shop.example/hooksonce, when you set it up…later, a customer paysPOST /hooks · payment.succeeded200 OKno polling
Instead of asking “paid yet?” every few seconds, your app gives the other service a URL and is told the moment something happens.

Key takeaways

  • A webhook is an HTTP request triggered by an event.
  • The sender pushes data to you, so you don't have to poll.
  • You provide the URL; the other service calls it.
  • Verify signatures, because anyone can send requests to a public URL.
  • Expect retries and make your handler safe to run more than once.

Example

Receiving a webhook in Express.jsjavascript
// Receive webhook events from a payment provider
app.post("/webhooks/payments", express.json(), (req, res) => {
  // In production, verify the request's signature header first
  const event = req.body;

  if (event.type === "payment.succeeded") {
    markOrderAsPaid(event.data.orderId);
  }

  // Reply quickly with 200 so the sender does not retry
  res.sendStatus(200);
});

Readers ask

What is the difference between a webhook and an API?

With a regular API call, your application requests data when it wants it. With a webhook, the other application sends data to you automatically when an event happens, so webhooks are often described as event-driven or reverse APIs.

What is the difference between a webhook and polling?

Polling means asking a server for updates on a fixed schedule, even when nothing has changed. A webhook delivers the update once, right when it happens, which is faster and uses far fewer requests.

How do I secure a webhook?

Use HTTPS, verify the signature the sender includes in the request headers using a shared secret, and reject requests that fail the check or are too old.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings