Webhooks are not ordinary form submissions
Payment and automation providers send server-to-server events. They may retry requests, deliver events out of order or send duplicate notifications. Never trust a user-submitted success URL as proof of payment.
Verification steps
1. Capture the raw request body before changing it. 2. Verify the provider's signature using its maintained SDK and endpoint secret. 3. Check a replay-resistant timestamp where supported. 4. Store event IDs under a unique database constraint. 5. Acknowledge promptly and move slow processing to a queue when possible.
Model
Receive HTTPS event
→ verify signature
→ validate expected event type
→ insert unique event_id
→ process once
→ record outcome
Failure behavior
Respond with appropriate non-success codes for temporary failures, log only redacted payload metadata, and implement a manual reconciliation path.
The correct signature format depends on the provider; use its current official developer documentation and SDK rather than a generic homemade digest.
Examples are starting points, not production security audits. Confirm dependencies, versions and pricing using linked vendor documentation.