What is a Webhook?
A webhook is an HTTP request sent by one system to notify another that an event occurred. Reliable implementations verify signatures, tolerate retries, and process duplicate deliveries idempotently.
How Webhooks work
A webhook producer serializes an event and sends it to a consumer-controlled HTTP endpoint, decoupling asynchronous state changes from polling. Delivery is normally at least once rather than exactly once, because a lost response leaves the sender unable to know whether processing succeeded. The receiver therefore authenticates the original request, records an event identity, acknowledges promptly, and moves expensive media or business work to a durable queue.
Key facts
- 1Providers define exactly what is signed: some sign the raw request bytes plus a timestamp, while Transloadit sends an HMAC of the
transloaditfield in its multipart notification, computed with your Auth Secret. Verify the payload the provider defines, never a reserialized version of it. - 2Returning a success response only after lengthy downstream work increases timeouts and retries; persisting the event before acknowledging allows processing to continue asynchronously.
- 3Retries can duplicate or reorder events, so the event identifier and current resource version are safer guards for side effects than assuming each endpoint call is unique.
When Webhooks matter
Webhooks can continue application logic when asynchronous media processing completes or fails. Consumers must authenticate requests and avoid repeating side effects when the sender retries an event.
Common use cases for platform workflows
These examples cover platform workflows broadly, not specifically Webhooks.
- Running repeatable upload, import, processing, AI, storage, and notification pipelines.
- Tracking long-running media work independently from an application request.
- Referencing centrally stored credentials by name instead of sending storage secrets with each request.
Working with platform workflows
This guidance covers platform workflows broadly, not just Webhooks.
A client authenticates and submits files or references together with workflow instructions. The platform validates the request, schedules dependent operations, records state transitions, and exposes results through a response, polling endpoint, or notification.
Platform concepts become reliable only when their lifecycle is explicit. Authentication, idempotency, retries, timeouts, observability, quotas, and terminal states should be designed together rather than added after failures occur.
What you gain
- Reusable workflows separate application intent from processing infrastructure.
- Stable job identifiers and lifecycle events improve observability and recovery.
- Managed queues and workers let products scale without embedding every media tool.
What it costs
- Synchronous responses are simple but keep connections open while long work executes.
- Aggressive retries improve recovery from transient faults but can duplicate work or overload a dependency.
- Higher concurrency reduces queue time until resource contention or a downstream limit becomes the bottleneck.
Before production
- 1Define authentication, authorization, idempotency, retries, and terminal error behavior.
- 2Observe queue time, execution time, callbacks, and partial results with stable identifiers.
- 3Exercise malformed, duplicate, interrupted, and unauthorized requests before launch.