webhook-handler-patterns
>
Works with
--- name: webhook-handler-patterns description: > license: MIT --- # Webhook Handler Patterns ## When to Use This Skill - Following the correct webhook handler order (verify → parse → handle idempotently) - Implementing idempotent webhook handlers - Handling errors and configuring retry behavior - Understanding framework-specific gotchas (raw body, middleware order) - Building production-ready webhook infrastructure ## Resources ### Handler Sequence - [references/handler-sequence.md](references/handler-sequence.md) - Verify first, parse second, handle idempotently third ### Best Practices - [references/idempotency.md](references/idempotency.md) - Prevent duplicate processing - [references/error-handling.md](references/error-handling.md) - Return codes, logging, dead letter queues - [references/retry-logic.md](references/retry-logic.md) - Provider retry schedules, backoff patterns ### Framework Guides - [references/frameworks/express.md](references/frameworks/express.md) - Express.js patterns and gotchas - [references/frameworks/nextjs.md](references/frameworks/nextjs.md) - Next.js App Router patterns - [references/frameworks/fastapi.md](references/frameworks/fastapi.md) - FastAPI/Python patterns ## Quick Reference ### Handler Sequence 1. **Verify signature first** — Use raw body; reject invalid requests with 4xx. 2. **Parse payload second** — After verification, parse or construct the event. 3. **Handle idempotently third** — Check event ID, then process; return 2xx for duplicates. See [references/handler-sequence.md](references/handler-sequence.md) for details and links to provider verification and idempotency patterns. ### Response Codes | Code | Meaning | Provider Behavior | |------|---------|-------------------| | `2xx` | Success | No retry | | `4xx` | Client error | Usually no retry (except 429) | | `5xx` | Server error | Retry with backoff | | `429` | Rate limited | Retry after delay | ### Idempotency Checklist 1. Extract unique event ID from payload 2. Check if event was already processed 3. Process event within transaction 4. Store event ID after successful processing 5. Return success for duplicate events ## Related Skills - [stripe-webhooks](https://github.com/hookdeck/webhook-skills/tree/main/skills/stripe-webhooks) - Stripe payment webhook handling - [shopify-webhooks](https://github.com/hookdeck/webhook-skills/tree/main/skills/shopify-webhooks) - Shopify e-commerce webhook handling - [github-webhooks](https://github.com/hookdeck/webhook-skills/tree/main/skills/github-webhooks) - GitHub repository webhook handling - [resend-webhooks](https://github.com/hookdeck/webhook-skills/tree/main/skills/resend-webhooks) - Resend email webhook handling - [chargebee-webhooks](https://github.com/hookdeck/webhook-skills/tree/main/skills/chargebee-webhooks) - Chargebee billing webhook handling - [clerk-webhooks](https://github.com/hookdeck/webhook-skills/tree/main/skills/clerk-webhooks) - Clerk auth webhook handling - [elevenlabs-webhooks](https://github.com/hookdeck/webhook-skills/tree/main/skills/elevenlabs-webhooks) - ElevenLabs webhook handling - [openai-webhooks](https://github.com/hookdeck/webhook-skills/tree/main/skills/openai-webhooks) - OpenAI webhook handling - [paddle-webhooks](https://github.com/hookdeck/webhook-skills/tree/main/skills/paddle-webhooks) - Paddle billing webhook handling - [hookdeck-event-gateway](https://github.com/hookdeck/webhook-skills/tree/main/skills/hookdeck-event-gateway) - Webhook infrastructure that replaces your queue — guaranteed delivery, automatic retries, replay, rate limiting, and observability for your webhook handlers
More API Design skills
lark-event
larksuite/cli
Lark/Feishu real-time event listening / subscribing / consuming: stream events as NDJSON via `lark-cli event consume <EventKey>` (covers IM messages/reactions/chat changes, Approval status changes, Task updates, VC meeting started/joined/ended, Minutes generated, Whiteboard updated, etc.). Use for Lark bots, real-time message processing, long-running subscribers, streaming webhook/push handlers. Supports `--max-events` / `--timeout` bounded runs and a stderr ready-marker contract — designed for AI agents running as subprocesses.
lark-contact
larksuite/cli
飞书 / Lark 通讯录:按姓名 / 邮箱解析成 open_id,或按 open_id 反查姓名 / 部门 / 邮箱 / 联系方式 / 个人状态 / 签名,以及按关键词搜索当前用户可见的机器人 / 智能体(agent)。当用户提到一个名字要下一步发消息 / 排日程,或拿到 open_id 想查具体信息时使用。不负责部门树遍历、按部门列员工、组织架构图,这类需求走原生 OpenAPI。
lark-openapi-explorer
larksuite/cli
飞书/Lark 原生 OpenAPI 探索:从官方文档库中挖掘未经 CLI 封装的原生 OpenAPI 接口。当用户的需求无法被现有 lark-* skill 或 lark-cli 已注册命令满足,需要查找并调用原生飞书 OpenAPI 时使用。

