Build webhook payloads, generate cURL commands, calculate HMAC signatures, and explore webhook formats for GitHub, Stripe, Slack, Discord and more. 100% client-side, no signup needed.
No requests saved yet. Build a webhook request and click "Save to History".
A webhook is an HTTP callback that sends real-time data from one application to another when a specific event occurs. Instead of polling an API, the server pushes data to your endpoint automatically.
Content-Type: application/json — Standard JSON payload
X-Hub-Signature-256 — GitHub HMAC-SHA256 signature
Stripe-Signature — Stripe webhook signature (t=timestamp,v1=signature)
X-Slack-Signature — Slack request signature
X-Request-Id — Unique request identifier for idempotency
User-Agent — Identifies the sending service
1. Verify signatures — Always validate HMAC signatures to ensure the request comes from the expected source.
2. Use HTTPS — Never accept webhooks over plain HTTP.
3. Idempotency — Handle duplicate deliveries gracefully using unique event IDs.
4. Respond quickly — Return 200 OK within 5 seconds; process asynchronously.
5. Rate limiting — Implement rate limiting to prevent abuse.
POST — Most common, used by GitHub, Stripe, Slack, Discord
PUT — Sometimes used for update events
GET — Used for verification/challenge responses (Slack, Facebook)
DELETE — Rare, sometimes used for unsubscribe events
Most webhook providers retry failed deliveries using exponential backoff:
GitHub: 1 retry after a short delay
Stripe: Up to 72 hours with increasing intervals (1h, 2h, 4h, 8h...)
Slack: 3 retries within 30 minutes
Shopify: 19 retries over 48 hours
Let us build it for you. Custom APIs, dashboards, automations — whatever you need.
Start a Project →269 free tools. No signup. Open source. Built by Christian Bucher.