Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Webhook Failure Triage & Safe Retry

    1

    Classify failed or uncertain webhooks and return an evidence-grounded RETRY, DO_NOT_RETRY, or RECONCILE_FIRST verdict.

    $7

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    Webhook Failure Triage & Safe Retry

    Webhook Failure Triage & Safe Retry

    Example session with this skill installed

    Stripe shows that the synthetic invoice.paid event evt_demo_123 was delivered at 10:00:05 UTC. Our edge log records a 504 at 10:00:35 UTC, and the subscription dashboard still shows past_due. We do not yet have the receiver application log or an authoritative ledger lookup. The handler is intended to deduplicate on the Stripe event ID, but we have not verified the deduplication store. Is it safe to replay this event?

    • Read your context and instructions
    • Compiled the webhook failure triage
    • Generated the document

    Webhook Triage Report

    VERDICT: RECONCILE_FIRST
    PRIMARY_STATE: UNKNOWN
    Confidence: High that the evidence is insufficient; low on the actual commit state.

    The 504 shows that a gateway did not receive a timely upstream response. It does not prove whether the application rejected the event, failed before the side effect, committed the side effect and lost the acknowledgement, or never received it.

    Canonical timeline

    Time (UTC)LayerSupplied evidenceWhat it proves
    10:00:05ProviderStripe marks evt_demo_123 deliveredA provider-recorded delivery outcome, not the internal commit state
    10:00:35Edge504 recordedA timely upstream response was not received
    Current snapshotSubscription viewStatus remains past_dueThe visible projection is not updated; an internal ledger commit is still unproven

    Evidence assessment

    ClaimLabelAssessment
    A 504 occurredOBSERVEDSupplied edge-log fact
    No business side effect occurredUNKNOWNNo authoritative ledger or receiver evidence was supplied
    Event-ID deduplication will prevent duplicationUNKNOWNIntended behavior is stated, but the store and atomic enforcement are unverified
    Immediate replay is safeUNKNOWNCommit state and idempotency must be reconciled first

    Duplicate-impact radius

    A duplicate could affect the subscription period, billing ledger, entitlement state, and customer notification. Do not use the dashboard alone as proof that none of these changed.

    Minimum checks before any replay

    1. Query the event-processing or deduplication record for evt_demo_123.
    2. Check the authoritative billing ledger and subscription record for the expected side effect.
    3. Correlate receiver logs using the event ID and the 10:00:05–10:00:35 UTC window.
    4. Confirm that a replay preserves the original event identity and that deduplication is enforced atomically with the side effect.

    Decision path

    • If the authoritative side effect is absent and atomic deduplication is verified, the verdict may change to RETRY.
    • If the side effect or processed-event record exists, use

    DO_NOT_RETRY and reconcile the acknowledgement or projection instead.

    • If either fact remains unavailable, keep RECONCILE_FIRST.

    No replay has been executed. A human must authorize any payment-affecting action after the checks above.

    webhook-failure-triage-safe-retry.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Classify one failed or uncertain webhook as not delivered, rejected, processing failed, processed with acknowledgement lost, duplicate, or unknown.Receive a RETRY, DO_NOT_RETRY, or RECONCILE_FIRST verdict grounded in the supplied evidence.Map provider attempts, receiver responses, processing steps, and business side effects into a canonical timeline.Identify the minimum safe checks and duplicate-impact radius before any manual replay.

    About this skill

    The problem

    A webhook can time out or return an error after part of the business operation has already committed. Replaying too early can duplicate a payment, order, entitlement, message, or ledger entry. A 2xx response also does not prove that every downstream side effect completed.

    What it does

    • Classifies the supplied evidence as NOT_DELIVERED, DELIVERED_REJECTED, DELIVERED_PROCESSING_FAILED, PROCESSED_ACK_LOST, DUPLICATE, or UNKNOWN.
    • Builds a canonical timeline that separates provider attempts, receiver acknowledgements, processing steps, and business side effects.
    • Returns one bounded verdict: RETRY, DO_NOT_RETRY, or RECONCILE_FIRST.
    • Identifies duplicate-impact radius, minimum discriminating checks, unresolved facts, and a safe retry plan when retry is justified.

    What you provide

    Redacted provider status, event or delivery IDs, timestamps and timezone, HTTP response or timeout evidence, receiver logs, expected side effect, current authoritative state, and verified idempotency or deduplication behavior. Never provide signing secrets, tokens, cookies, private keys, or full customer records.

    What you receive

    • A clear verdict and primary state with confidence.
    • An evidence table labeled OBSERVED, DERIVED, or UNKNOWN.
    • A canonical timeline and duplicate-impact analysis.
    • The minimum checks required before any action.
    • A bounded retry plan with prerequisites, verification, and stop conditions when RETRY is justified.

    Why this is different

    The skill does not equate a 2xx response with business completion, or a timeout or 5xx response with a safe retry. It prefers RECONCILE_FIRST when commit state or idempotency is unproven and never performs the replay itself.

    Known limitations

    It uses only the redacted evidence the user supplies. It does not access production systems, provider dashboards, APIs, queues, databases, files, or secrets, and it cannot prove root cause when logs are incomplete. High-impact retries require human authorization after reconciliation.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 17 days ago

    • Passed all security checks, Safe to install

    Listed17 days ago

    What's inside

    Frequently Asked Questions