Webhook ingress

Receive events from other systems, checked, stored and replayable.

Built on Standard Webhooks

Plans: Every plan, including the free app

What you get

  • One receiving address for each source
  • Signatures checked before your app sees a delivery
  • Ready-made checks for Stripe, Shopify, Xero, GitHub and others
  • Every delivery stored, with retries
  • Replay any delivery to your app
  • An optional list of allowed IP addresses

How it works

You name a source in whisk.yaml, such as Shopify, with the secret that signs its deliveries. Whisk gives you an address to paste into that system. Each delivery is checked against its signature, stored, and passed to a route in your app.

If your app does not answer in time, Whisk tries again over several hours, then keeps the delivery so it can be replayed. Each delivery carries a stable id, so the app can ignore one it has already handled. The handler cannot be reached from the internet, only by Whisk.

Signature checks are configuration, not code, and include the open Standard Webhooks format. Systems without a ready-made check use a general HMAC setting. Deliveries often start a durable workflow.

Example

An auto parts distributor receives every Shopify order through a webhook and passes it to its warehouse system. When the warehouse system was down for an hour of maintenance, the orders waited and arrived once it was back.

For your coding agent

secrets: [SHOPIFY_WEBHOOK_SECRET]
webhooks:
  - name: shopify
    preset: shopify
    secret: SHOPIFY_WEBHOOK_SECRET
    handler: /hooks/shopify

whisk webhooks list prints the address, whisk webhooks events shopify lists recent deliveries and whisk webhooks replay shopify <id> sends one again. Every field is in the whisk.yaml reference.

Read more

All features