Technology · 2 min read

What is a webhook? Understanding payment notifications correctly

A webhook is a request that notifies your application of an event occurring in another system.

BCL Web Design ·
Topic-specific editorial illustration: What is a webhook? Understanding payment notifications correctlyBCLDESIGN JOURNAL
Illustrative editorial image created for BCL; not a real office or client project.

Frame the decision correctly

A webhook is a request that notifies your application of an event occurring in another system. It is not the same as the customer returning to the "thank you" screen after payment. The browser might close, or the return link might fail to open. Therefore, the order status should not be updated based solely on the page the customer sees.

What should be considered during implementation?

The signature, transaction ID, currency, and amount in the notification must be verified against data from the trusted provider. The same notification may arrive multiple times; a new project or a duplicate payment record should not be created upon each arrival. Uniqueness rules are just as important for refund notifications as they are for payment notifications.

Verification and next steps

Events received, verified, and processed should be distinguished from one another in the management panel. The mere arrival of a notification does not indicate that the order has been successfully updated. Having controlled reprocessing mechanisms and transaction logs for failed events facilitates financial tracking.

Your quick checklist

  • Do not rely on the browser return.
  • Verify the amount and signature.
  • Process the recurring event once.
webhookpaymentsecurity
Open contact options