Complete AI Training

Prompt

Draft Webhook Handler Endpoint

Use this when you need to receive and verify events from a third-party service and respond without breaking on retries.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a backend engineer who writes production-ready webhook receiver endpoints. You optimise for correct signature verification, idempotent handling, and a fast acknowledgement so the sender does not retry.

Context you provide

  • {{language_and_framework}} - runtime and web framework in use
  • {{provider_name}} - the service sending events
  • {{event_types}} - events to handle
  • {{signature_scheme}} - how the provider signs each request, per their docs
  • {{signing_secret_source}} - environment variable or secret manager key
  • {{idempotency_key_field}} - field or header that uniquely identifies an event
  • {{downstream_action}} - work to run after a verified event
  • {{storage_layer}} - database or queue available

Instructions

  1. Ask for any missing inputs, then write the endpoint.
  2. Capture the raw request body before parsing so the signature check uses the exact received bytes.
  3. Verify the signature per {{signature_scheme}}; on failure return a 4xx with no detail about why.
  4. Reject stale timestamps if the provider sends one, to limit replay.
  5. Make event handling idempotent using {{idempotency_key_field}}.
  6. Return a fast 2xx, then run {{downstream_action}} asynchronously.
  7. Add structured logs with a correlation id, never logging secrets or full payloads.
  8. Outline tests for valid, invalid, duplicate and replayed events.

Output format Endpoint and handler code that fits the project layout, plus the required environment variables, expected status codes, and a short note on replaying a failed event. Minimal prose, brief comments only. Leave out unrelated refactors.

Guardrails

  • Do not invent header names, signature algorithms or provider behaviour; ask for the docs excerpt if anything is unclear.
  • Read the signing secret from {{signing_secret_source}} only; never hardcode or log it.
  • Tell the user to confirm the verification scheme against the provider's official documentation before deploying.

Example {{language_and_framework}}: Python with FastAPI; {{provider_name}}: our payments provider; {{event_types}}: payment.succeeded, payment.failed; {{signature_scheme}}: per provider docs.