Webhook Delivery Security Lab (Interactive)
Deliver one payment event to healthy, down, hanging, forged, and replayed receivers while toggling HMAC and backoff defenses. Watch exponential-backoff attempts across the 72-hour schedule, 5-second timeout shedding, constant-time signature rejection, and duplicate-event dedupe play out attempt by attempt.
Signed Webhook Delivery & Retry Engine
Dispatch one payment event at hostile receivers and toggled defenses; watch HMAC, timeouts, and backoff do their jobs.
POST https://merchant.example.com/webhook
Stripe-Signature: t=1714000000,v1=cbb78436cbb7…8436cbb78436
{"id":"evt_3N4L9f2e","type":"payment.succeeded","amount":50000}
// schematic digest shown for teaching; production = crypto.createHmac('sha256', whsec) over t + "." + raw_body
How It Works Under the Hood
Webhooks are reverse APIs fired at third-party servers you do not control, and every hazard of that shows up: receivers hang and exhaust dispatch worker sockets unless a strict 5-second timeout applies, go dark for maintenance and need an eight-step exponential backoff spanning 72 hours before auto-disable, and anyone who learns the merchant URL can POST fake payment.succeeded events. HMAC-SHA256 over the timestamp plus raw body, verified with constant-time comparison inside a five-minute tolerance window, defeats forgery and replay — but at-least-once retries still make receiver-side event-id dedupe mandatory.
Core Architectural Principles
- Signature = HMAC-SHA256(secret, timestamp + "." + raw_body) sent as t=…,v1=… and compared timing-safe.
- Retry ladder 0s→1m→5m→30m→2h→8h→24h→72h, then endpoint DISABLED with developer email and manual replay.
- 5s read timeouts shed hanging receivers; event-id dedupe absorbs the duplicates backoff guarantees.
Design webhooks in three sentences the interviewer wants: sign payloads with HMAC-SHA256 including a timestamp so replays die at the tolerance check, retry on non-2xx with capped exponential backoff over 72h then disable, and tell consumers delivery is at-least-once so they must dedupe by event id. Add dashboard logs plus manual resend as the DX story.
Real-time push integration convenience against multi-day retry state, timeout policing, and signature infrastructure.