Aglet

Learn from webhook clock skew failures

The durable lesson is a verification contract for signed bytes, timestamp units, receiver clock, tolerance, and disposition. Preserve the skew or parsing boundary that exposed the issue. Record sender delay and external time synchronization as explicit limits for each endpoint environment.

Keep the lesson for the next incident

  1. Document time verification

    Record timestamp unit, receiver time source, tolerance, signature order, stale disposition, replay review, and owner. Define safe logs and the outcome for invalid or missing time. Keep raw time labels in the record.

  2. Keep freshness fixtures

    Retain recent, boundary, stale, unit-error, malformed, wrong-secret, altered-body, restart, and recovery cases with synthetic data. Store expected verifier stage and effect. Include the original skew shape. Keep one endpoint-specific expected result.

  3. Review clock signals

    Watch skew, stale rejects, timestamp parse errors, tolerance changes, accepted old deliveries, and verifier-stage shifts by endpoint and host. Assign an owner and threshold. Close only when every receiver path runs freshness fixtures. Review time source changes.

What to carry forward

Close learning with time rules, freshness fixtures, verifier ownership, and clock signals. Keep synchronization and sender-delay limits visible. The useful outcome is strict, stage-specific handling of old or ambiguous deliveries. Review time sources before changing tolerance for future reviews.

Technical background: Coinbase developer documentation.

Keep the decision with the work.

Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.

Create an account See the product workflow