Glossary

What is a webhook?

Last reviewed 7 October 2026

Definition

A webhook is an HTTP request that one system sends automatically to a URL you provide whenever a chosen event happens, carrying data about that event. Instead of your code asking a service again and again whether anything changed, the service tells you when it does. The receiving URL is called the webhook endpoint.

Also called: web hook, HTTP callback, webhook endpoint, reverse API.

Why it matters

Why Webhook matters

Webhooks are how most modern software announces events to other software. A payment succeeds, a pull request opens, a form is submitted: the service that saw it sends a webhook, and the receiving system acts. GitHub's documentation sets out the case against the alternative, polling: webhooks need less effort and fewer resources, and they arrive in near real time because they fire when the event happens.

For automation, the webhook is usually the trigger. It decides how quickly a workflow starts and whether it starts at all, so understanding delivery, failure and duplicates saves a lot of debugging later.

Mechanism

How it works

You register an endpoint with the sending service and choose which event types it should receive. Stripe, for example, asks for a publicly accessible HTTPS URL and lets you pick the events. When one of those events occurs, the service sends a POST request to your URL with a JSON body describing the event.

Your endpoint must check that the request is genuine, because anyone who knows the URL can send it data. Stripe signs each delivery with an HMAC SHA-256 signature in a Stripe-Signature header, computed with a secret only you and Stripe hold, and includes a timestamp so old requests can be rejected. Other providers use similar shared-secret schemes.

Your endpoint should reply with a 2xx status quickly and do slow work afterwards, because the sender treats a slow or failed reply as a failed delivery. On Stripe's page read on 7 October 2026, live-mode deliveries are retried for up to three days with exponential back-off. Retries mean the same event can arrive twice, and Stripe says events may not arrive in the order they were created, so handlers record event IDs and ignore repeats.

Worked example

Worked example: a payment confirms an order

A shop registers an endpoint for its payment provider's payment succeeded event. A customer pays. Shortly afterwards the provider posts the event to the shop's endpoint. The handler verifies the signature, checks the event ID against a table of processed events, stores the new ID, puts the event on an internal queue and returns 200.

A worker then picks the event off the queue, marks the order as paid and asks the warehouse system to pick it. If the shop's server had been down when the event fired, the provider would have retried later, and the processed-events table would stop the order being handled twice if both deliveries eventually arrived.

Where Swfte stands

How Swfte relates to it

Built in the product

A Studio workflow can start from a webhook trigger, so a service such as a CRM, a form tool or a payment provider can start a workflow without you writing and hosting a receiving server. Model calls inside the workflow go through Connect.

Because a workflow that calls a model can take seconds or minutes, the pattern on the webhook owner page applies: acknowledge the delivery first, run the work after, and write results back through the source system's API. That page also covers debugging failed deliveries, which this glossary entry does not.

Keep reading
  • API integration

    API integration is the use of application programming interfaces (APIs) to connect software, so that one application can read data from, or trigger actions in, another through a documented interface.

  • Workflow

    A workflow is the ordered set of steps that takes one piece of work, such as a purchase request or a support ticket, from the event that starts it to a finished outcome.

  • iPaaS (integration platform as a service)

    iPaaS, short for integration platform as a service, is a hosted set of tools for connecting applications, data sources and systems without running your own integration servers.

  • Software integration

    Software integration is the work of connecting separate applications so they can share data and trigger actions in each other, making them behave like parts of one system.

  • Workflow automation

    Workflow automation is the use of software to run the steps of a repeatable process, such as passing data between systems, assigning tasks and requesting approvals, according to defined rules instead of by hand.

Common questions

What is the difference between a webhook and an API?
An API is an interface you call when you want something: you send a request and get a response. A webhook reverses the direction, because the other system calls you when something happens. Most webhook providers also have an API, and handlers often call it to fetch the full record an event refers to.
Is a webhook push or pull?
Push. The sending service starts the HTTP request to your endpoint when the event occurs. Polling is the pull alternative, where your code repeatedly asks the service whether anything changed. GitHub's documentation notes that webhooks need fewer resources than polling and deliver updates in near real time.
Are webhooks secure?
They can be, if the receiver does its part. Use HTTPS, verify the signature on every delivery with the shared secret, reject requests with old timestamps to block replays, and keep the secret out of code. Some providers, Stripe among them, also publish the IP addresses they send from, so you can restrict access further.
What happens if my webhook endpoint is down?
It depends on the sender. Many retry failed deliveries for a period and then give up. Stripe's documentation, read on 7 October 2026, describes retries for up to three days in live mode. Design the handler so a late or repeated delivery does no harm, and reconcile against the sender's API after an outage.
Evidence

Sources

Definitions on this page were read on the sources below on 7 October 2026. Where sources define the term differently, the page says so. The full glossary lists more terms.

  1. GitHub documentation on webhooks (read 2026-10-07)
  2. Stripe documentation on receiving webhook events (read 2026-10-07)

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.