Webhook ingress
Receive events from other systems, checked, stored and replayable.
Built on Standard Webhooks
Plans: Every plan, including the free app
What you get
- One receiving address for each source
- Signatures checked before your app sees a delivery
- Ready-made checks for Stripe, Shopify, Xero, GitHub and others
- Every delivery stored, with retries
- Replay any delivery to your app
- An optional list of allowed IP addresses
How it works
You name a source in whisk.yaml, such as Shopify, with the secret that signs its deliveries. Whisk gives you an address to paste into that system. Each delivery is checked against its signature, stored, and passed to a route in your app.
If your app does not answer in time, Whisk tries again over several hours, then keeps the delivery so it can be replayed. Each delivery carries a stable id, so the app can ignore one it has already handled. The handler cannot be reached from the internet, only by Whisk.
Signature checks are configuration, not code, and include the open Standard Webhooks format. Systems without a ready-made check use a general HMAC setting. Deliveries often start a durable workflow.
Example
An auto parts distributor receives every Shopify order through a webhook and passes it to its warehouse system. When the warehouse system was down for an hour of maintenance, the orders waited and arrived once it was back.
For your coding agent
secrets: [SHOPIFY_WEBHOOK_SECRET]
webhooks:
- name: shopify
preset: shopify
secret: SHOPIFY_WEBHOOK_SECRET
handler: /hooks/shopifywhisk webhooks list prints the address, whisk webhooks events shopify lists recent deliveries and whisk webhooks replay shopify <id> sends one again. Every field is in the whisk.yaml reference.