Multi-Vendor Webhook Foundation Several third-party providers — identity, e-signature, background...Multi-Vendor Webhook Foundation Several third-party providers — identity, e-signature, background...
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
Multi-Vendor Webhook Foundation
Several third-party providers — identity, e-signature, background checks — each push status updates via webhooks with different payloads, signing schemes, and retry behavior. Ad-hoc handlers meant duplicated verification logic and inconsistent failure handling.
I built a shared foundation handling signature verification, replay protection, idempotency, and dead-letter capture, with per-vendor adapters extending the base rather than forking it. Adding a provider became an adapter, not a subsystem.
Verification is fail-closed: an unverifiable webhook is rejected outright, never processed on the assumption it's probably genuine. A reconciliation job covers the case where a webhook never arrives at all.
Post image
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started