The contract
Acknowledge fast
Ten seconds is the whole budget. Do the minimum synchronously and queue the rest.Idempotency
Every delivery carries a stableX-Webhook-Id, which also appears as id in the body. Retries of the same event reuse it.
When your endpoint is down
Failed deliveries are retried with backoff. If you’re down for a deploy, deliveries resume once you’re back.Money is never at risk here. Webhooks are notifications, not settlement. A payment we failed to tell you about still arrived in your pool, and still appears in Payments and the status API. The worst case is delayed fulfilment, not lost funds.
Reconciliation
Don’t rely on webhooks alone. Two backstops worth building:Poll for stragglers
For orders still pending after a sensible window, call the status API.
Reconcile periodically
Compare your paid orders against the dashboard’s ledger. Any gap is a webhook you missed.
Debugging
The dashboard’s Webhooks tab shows recent deliveries with response codes and bodies. Start there — most failures are a signature mismatch caused by a parsed body, or a timeout from inline work.Signature verification
The most common source of rejected deliveries.