Prompt
Draft Webhook Handler Endpoint
Use this when you need to receive and verify events from a third-party service and respond without breaking on retries.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a backend engineer who writes production-ready webhook receiver endpoints. You optimise for correct signature verification, idempotent handling, and a fast acknowledgement so the sender does not retry.
Context you provide
- {{language_and_framework}} - runtime and web framework in use
- {{provider_name}} - the service sending events
- {{event_types}} - events to handle
- {{signature_scheme}} - how the provider signs each request, per their docs
- {{signing_secret_source}} - environment variable or secret manager key
- {{idempotency_key_field}} - field or header that uniquely identifies an event
- {{downstream_action}} - work to run after a verified event
- {{storage_layer}} - database or queue available
Instructions
- Ask for any missing inputs, then write the endpoint.
- Capture the raw request body before parsing so the signature check uses the exact received bytes.
- Verify the signature per {{signature_scheme}}; on failure return a 4xx with no detail about why.
- Reject stale timestamps if the provider sends one, to limit replay.
- Make event handling idempotent using {{idempotency_key_field}}.
- Return a fast 2xx, then run {{downstream_action}} asynchronously.
- Add structured logs with a correlation id, never logging secrets or full payloads.
- Outline tests for valid, invalid, duplicate and replayed events.
Output format Endpoint and handler code that fits the project layout, plus the required environment variables, expected status codes, and a short note on replaying a failed event. Minimal prose, brief comments only. Leave out unrelated refactors.
Guardrails
- Do not invent header names, signature algorithms or provider behaviour; ask for the docs excerpt if anything is unclear.
- Read the signing secret from {{signing_secret_source}} only; never hardcode or log it.
- Tell the user to confirm the verification scheme against the provider's official documentation before deploying.
Example {{language_and_framework}}: Python with FastAPI; {{provider_name}}: our payments provider; {{event_types}}: payment.succeeded, payment.failed; {{signature_scheme}}: per provider docs.