- Home
- Skills
- APIs & Backend
- webhook reliability scaffold
Works with the AI tools you already use
webhook reliability scaffold
Generate production-grade, resilient webhook handlers with documented reliability constraints and validation tests.
$9
webhook reliability scaffold
Example session with this skill installed
I need a reliable webhook receiver in Node.js/Express using Redis for idempotency. I'm consuming Stripe events and need to handle duplicates and potential out-of-order delivery.
- Read your context and instructions
- Compiled the webhook reliability scaffold
The webhook receiver scaffold has been generated for a Node.js/Express stack using Redis. The implementation includes a constraint-verified handler, signature verification logic, and a per-event idempotency check.
WEBHOOK RELIABILITY SCAFFOLD — receiver · Node.js/Express/Redis
══════════════════════════════════════════════════════════
CONSTRAINT LEDGER
- C1 RETRY SAFETY: SATISFIED — Framework-level 2xx fast-ack; retry logic deferred to Stripe provider settings.
- C2 IDEMPOTENCY: SATISFIED — Redis
SETNXusingevt_ID with 24h TTL. - C3 AUTHENTICITY: SATISFIED —
stripe.webhooks.constructEventusing raw body before JSON parsing. - C4 REPLAY PROTECTION: SATISFIED — Stripe signature includes timestamp; 5-minute tolerance enforced.
C5 FAILURE VISIBILITY: SATISFIED — Failed processes logged to webhooks:dead_letter Redis list for manual replay.
- C6 FAST ACK: SATISFIED — Immediate 200 OK after ingestion to Redis queue.
- C7 ORDERING: SATISFIED — Per-customer sequential processing enforced via Redis-backed queue locks.
GENERATED ARTIFACT
const express = require('express');
const Redis = require('ioredis');
const stripe = require('stripe')(process.env.STRIPE_SECRET_KEY);
const redis = new Redis(process.env.REDIS_URL);
const app = express();
app.post('/webhook', express.raw({type: 'application/json'}), async (req, res) => {
const sig = req.headers['stripe-signature'];
let event;
// C3: Authenticity check before parsing
try {
event = stripe.webhooks.constructEvent(req.body, sig, process.env.STRIPE_WEBHOOK_SECRET);
} catch (err) {
return res.status(400).send(`Webhook Error: ${err.message}`);
}
// C2: Idempotency check
const lockKey = `webhook_idempotency:${event.id}`;
const isNew = await redis.set(lockKey, 'processed', 'NX', 'EX', 86400);
if (!isNew) return res.status(200).json({ received: true, duplicate: true });
// C6 & C7: Fast Ack and Queue for Processing
await redis.lpush('webhook_queue', JSON.stringify(event));
res.status(200).json({ received: true });
});
ALTERNATIVES CONSIDERED
Dedup mechanism: Chose Redis SETNX; rejected PostgreSQL unique constraint because high-volume spikes could saturate DB connections.
Ack strategy: Chose process-after-queue; rejected process-then-ack because Stripe's 10s timeout causes retry loops on long-running worker tasks.
VALIDATION GATE
- V1 DUPLICATE TEST: Send same Stripe ID twice; verify Redis key exists and second call returns
duplicate: true. - V2 FORGERY TEST: Send payload with invalid signature; verify 400 status returned before processing.
- V4 CRASH TEST: Stop worker after Lpush; verify event remains in
webhook_queuefor next worker start.
Next steps
- Set
STRIPE_WEBHOOK_SECRETin your environment variables. - Implement the background worker to consume the
webhook_queuelist. - Configure your dead-letter alert threshold in your monitoring tool.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Webhooks fail in ways that demos don't show: duplicate charges from multiple deliveries, unverified payloads allowing forgeries, and out-of-order events that break data integrity. Standard boilerplate handlers often ignore these edge cases, leading to silent data loss or race conditions in production.
What it does
- Generates a production-grade webhook consumption or delivery layer for specific stacks.
- Implements exponential backoff with jitter and replay protection to handle service instability.
- Builds idempotency logic to prevent duplicate processing of the same event.
- Enforces signature verification before payload parsing to prevent injection attacks.
- Produces a dead-letter strategy to ensure failed events are captured, never dropped.
Frameworks & tools
Works with any language or framework including Node.js, Python, Go, and Ruby. Supports integrations with Redis, SQS, PostgreSQL, and providers like Stripe, GitHub, and Shopify.
Why this beats prompting it yourself
This skill uses a Generative/Synthetic reasoning engine to document why specific design choices were made over rejected alternatives. It forces a constraint ledger that maps every reliability requirement to a concrete validation test, ensuring no silent failures in the architecture.
Use cases
- Building a Stripe payment handler that prevents double-fulfillment on duplicate webhooks.
- Scaling webhook ingestion for high-volume event streams (100+ events/sec).
- Securing custom internal webhooks with robust signature verification and replay windows.
- Scaffolding a resilient delivery system that handles target service downtime without data loss.
Known limitations
Cannot diagnose live incidents from existing logs. Does not invent signing algorithms for unknown providers; it provides the implementation slot for their specific scheme.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 22 days ago
- Passed all security checks, Safe to install