Webhooks vs Polling HMAC Lab (Interactive)
Pick push, short-poll, or long-poll, then sign, tamper, and replay deliveries live. Compare polling waste and detection latency against webhook push, then verify HMAC-SHA256 signatures with a 5-minute replay window on an ingestion receiver.
Polling vs Webhooks & the HMAC Gauntlet
Price three integration protocols per day, then attack your own receiver with tampering and replay captures.
API Calls / Day
2,040
events + ~2% redeliveries
Empty / Wasted
0%
responses with no new data
Detect Delay
30 ms
avg time to notice an event
Receiver ACK
22 ms
verify → SQS → 200 OK (fast-ACK)
Signature lab — simulated now: 1700000000
accepted
0
tampered
0
replays
0
sig = HMAC(secret, t + "." + rawBody) · window ±300s
RECEIVER LOG
› Receiver listening on POST /webhooks/stripe (public URL).
GitHub's deploy webhooks and Stripe's payment events cross the public Internet, so the receiver must be fast (validate → enqueue → 200 OK in <30 ms or the provider retries into a storm) and paranoid (constant-time HMAC compare + 5-minute timestamp window). A public endpoint at 20k events/day is fine; 1M internal eps belongs on Kafka, not JSON over HTTPS.
How It Works Under the Hood
Polling pays for silence: an API queried every 5 seconds for 100 daily events burns 17,280 calls to find 100 answers, while long polling holds sockets to shrink latency. Webhooks invert the model—the provider pushes on change—but you inherit three hazards: spoofing, replays, and slow handlers. The defenses are verifying HMAC-SHA256 signatures over the raw body within a timestamp replay window, returning 2xx instantly, and doing the real work behind a queue so a vendor’s retry storm never defines your business logic.
Core Architectural Principles
- Calls/day = subscribers × 86,400 / poll interval; waste ratio versus actual events makes polling’s tax visible.
- Valid HMAC passes, tampered payloads fail the signature, and stale timestamps fall outside the 300s replay window.
- Fast-ACK pattern: verify signature, enqueue, return 200 in milliseconds—processing retries come from the queue.
When asked about third-party integrations, answer webhook with a queue behind it: "verify HMAC over the raw body, check timestamp inside a replay window, persist the event, ack immediately, process asynchronously." Mention idempotency keys because vendors redeliver, and contrast with polling’s rate-limit tax when events are rare.
Webhooks deliver push latency and cut call volume but make you own signature security, retries, and exactly-once illusions.