Webhooks deep-dive: signatures, retries, idempotency
Channel: Evolve · Duration: 17:55 · Published: February 26, 2026 · 24,701 views
The full webhook story for production-ready integrations. Signature verification across all four SDKs, the retry schedule (1m, 5m, 30m, 2h, 12h, 1d, 3d, 7d), idempotency window sizing, dead-letter handling, and the one mistake that almost everyone makes the first time.
Chapters
- 0:00 — What webhooks are for (and what they aren't)
- 1:45 — Signature verification: HMAC-SHA-256, replay protection
- 5:30 — The retry schedule and why it ramps the way it does
- 9:12 — Idempotency: keys, windows, and de-dup at scale
- 12:48 — Dead-letter handling and account-contact emails
- 15:20 — The one mistake everyone makes (parsing the message field for branching)
Transcript highlights
"…tune your idempotency window to at least 7 days. Our last retry attempt is at the 7-day mark. If your window is shorter than that, a successful late delivery can collide with a manual retry from your ops team and you end up double-processing…"
"…signature verification isn't optional. Even if you whitelist our IPs, IPs change. The signature is a 30-second per-customer engineering task that catches a real category of attacks…"