Webhook
In short
A webhook is an automated HTTP request that one application sends to a URL you provide as soon as a specific event happens, such as a completed payment.
What is a webhook?
A webhook lets one system notify another the moment something happens. You register a URL with a service, and when a chosen event occurs, such as a new order, a failed payment, or a push to a code repository, the service sends an HTTP POST request to that URL with details about the event, usually in JSON format.
Webhooks are the opposite of polling. With polling, your app repeatedly asks an API whether anything has changed, which wastes requests and adds delay. With a webhook, the other service pushes the information to you only when there is something new, which is why webhooks are sometimes called reverse APIs.
An everyday analogy is the difference between refreshing a package-tracking page every few minutes and getting a text message when the package arrives. Webhooks are widely used by payment providers, chat tools, Git hosting services, and CI/CD pipelines to trigger automated work.
Because a webhook URL is publicly reachable, the receiver should verify each request, typically by checking a signature computed with a shared secret. Receivers should also respond quickly with a 2xx status code and handle duplicate deliveries safely, since most senders retry when a delivery fails.
At a glance
Key takeaways
- A webhook is an HTTP request triggered by an event.
- The sender pushes data to you, so you don't have to poll.
- You provide the URL; the other service calls it.
- Verify signatures, because anyone can send requests to a public URL.
- Expect retries and make your handler safe to run more than once.
Example
// Receive webhook events from a payment provider
app.post("/webhooks/payments", express.json(), (req, res) => {
// In production, verify the request's signature header first
const event = req.body;
if (event.type === "payment.succeeded") {
markOrderAsPaid(event.data.orderId);
}
// Reply quickly with 200 so the sender does not retry
res.sendStatus(200);
});Readers ask
What is the difference between a webhook and an API?
With a regular API call, your application requests data when it wants it. With a webhook, the other application sends data to you automatically when an event happens, so webhooks are often described as event-driven or reverse APIs.
What is the difference between a webhook and polling?
Polling means asking a server for updates on a fixed schedule, even when nothing has changed. A webhook delivers the update once, right when it happens, which is faster and uses far fewer requests.
How do I secure a webhook?
Use HTTPS, verify the signature the sender includes in the request headers using a shared secret, and reject requests that fail the check or are too old.
See also
- APIBackend & APIs, p. 2An API is a set of rules that lets one piece of software request data or actions from another in a predictable, documented way.
- HTTPWeb Development, p. 19HTTP is the protocol that browsers, apps, and servers use to exchange web pages and data through a simple cycle of requests and responses.
- EndpointBackend & APIs, p. 12An endpoint is a specific URL, combined with an HTTP method, where an API receives requests and returns responses for one particular resource or action.
- CallbackProgramming Fundamentals, p. 7A callback is a function passed as an argument to another function, which then calls it later, for example when a task finishes or an event happens.
- JSONBackend & APIs, p. 25JSON is a lightweight, text-based format for storing and exchanging structured data as key-value pairs and lists, readable by both humans and machines.
- CI/CDDevOps & Cloud, p. 9CI/CD is a set of automated practices that build, test, and release code changes frequently, so software can be delivered to users quickly and safely.
- SSRFSecurity, p. 42SSRF is a vulnerability where an attacker makes a server send requests to a destination of their choice, often reaching internal systems they can't access.
Spotted a mistake or something missing on this page?Suggest an edit