
A webhook is a request another service makes to you when something happens. In a PHP file on your site you receive it in four steps: read the raw body, check the signature, answer quickly and handle it afterwards. The signature step is what stops anyone who discovers the address from sending you fake data.
The skeleton, in four steps
|
|
|
|
Proving it works, without waiting for the service
|
|
|
When the webhook does not arrive or is refused
| Symptom | Likely cause |
| The signature never matches | A different secret, or the body was changed before you calculated (parsed and rewritten). |
| The service uses a different format | Some add a prefix to the value, such as the algorithm name. Follow the service’s documentation. |
| The request arrives as GET, with no body | A redirect from http to https, or from www to non-www, turns the POST into a GET. Use the final address. |
| 403 before it reaches PHP | A security rule or an IP block. See website errors explained. |
| The same event twice | Services resend when they do not get a 200. Store the event identifier and ignore repeats. |
A secret in the code is a secret in plain sight. Keep it in a file outside public_html, and do not put it in a repository. See keeping passwords out of your PHP code. And never trust the data of an unsigned webhook as if it were your own.
|
| Log each request received (time, result of the check, size of the body), without storing sensitive data. When the service swears it sent and you see nothing, the log tells you which side the problem is on. |
|
Want a plan with PHP to receive your webhooks? See the hosting plans. See the plans |
|
SEE ALSO What a webhook is, and how to test one with curl |
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $6.60/mo (3-year plan, with coupon) See plans |
- 0 Users Found This Useful











