Home/Labs/Webhook HMAC Ingestion Lab
All 280 Labs
INTERACTIVE LAB🔐

Webhooks vs Polling HMAC Lab (Interactive)

Pick push, short-poll, or long-poll, then sign, tamper, and replay deliveries live. Compare polling waste and detection latency against webhook push, then verify HMAC-SHA256 signatures with a 5-minute replay window on an ingestion receiver.

Polling vs Webhooks & the HMAC Gauntlet

Price three integration protocols per day, then attack your own receiver with tampering and replay captures.

API Calls / Day

2,040

events + ~2% redeliveries

Empty / Wasted

0%

responses with no new data

Detect Delay

30 ms

avg time to notice an event

Receiver ACK

22 ms

verify → SQS → 200 OK (fast-ACK)

Signature lab — simulated now: 1700000000

accepted

0

tampered

0

replays

0

sig = HMAC(secret, t + "." + rawBody) · window ±300s

RECEIVER LOG

› Receiver listening on POST /webhooks/stripe (public URL).

GitHub's deploy webhooks and Stripe's payment events cross the public Internet, so the receiver must be fast (validate → enqueue → 200 OK in <30 ms or the provider retries into a storm) and paranoid (constant-time HMAC compare + 5-minute timestamp window). A public endpoint at 20k events/day is fine; 1M internal eps belongs on Kafka, not JSON over HTTPS.

How It Works Under the Hood

Polling pays for silence: an API queried every 5 seconds for 100 daily events burns 17,280 calls to find 100 answers, while long polling holds sockets to shrink latency. Webhooks invert the model—the provider pushes on change—but you inherit three hazards: spoofing, replays, and slow handlers. The defenses are verifying HMAC-SHA256 signatures over the raw body within a timestamp replay window, returning 2xx instantly, and doing the real work behind a queue so a vendor’s retry storm never defines your business logic.

Core Architectural Principles

  • Calls/day = subscribers × 86,400 / poll interval; waste ratio versus actual events makes polling’s tax visible.
  • Valid HMAC passes, tampered payloads fail the signature, and stale timestamps fall outside the 300s replay window.
  • Fast-ACK pattern: verify signature, enqueue, return 200 in milliseconds—processing retries come from the queue.
Interview Round Script

When asked about third-party integrations, answer webhook with a queue behind it: "verify HMAC over the raw body, check timestamp inside a replay window, persist the event, ack immediately, process asynchronously." Mention idempotency keys because vendors redeliver, and contrast with polling’s rate-limit tax when events are rare.

Key Trade-Offs

Webhooks deliver push latency and cut call volume but make you own signature security, retries, and exactly-once illusions.

Related Curriculum Chapter

Webhooks vs Polling vs Message Queues

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs