Keep the lesson for the next incident
Document destination rules
Record canonical URL, environment, redirect policy, proxy ownership, method and body preservation, signature input, receipt, migration, rollback, and unapproved-target disposition. Specify whether a changed destination is permitted to receive the original payload and which component enforces that destination rule.
Keep route fixtures
Retain direct, reviewed redirect, path rewrite, method change, invalid target, signature, duplicate, and migration cases with synthetic events. Store expected request and receipt state. Include the original redirect shape. Retain the receiver response and signed request representation for the redirected case, so migration cannot conceal a changed verification input.
Review endpoint changes
Watch URL configuration, redirect statuses, target changes, missing receipts, signature failures, and duplicate attempts by endpoint. Assign an owner and threshold. Close the follow-up only when every configured destination has route coverage.
What to carry forward
Close learning with destination rules, route fixtures, migration ownership, and redirect signals. Keep sender behavior visible. The useful outcome is an explicit canonical endpoint and a safe response to any unexpected hop. After a rollback, compare the active canonical destination with the sender configuration and remove any assumption that both changed together.
Technical background: Stripe documentation.
Keep the decision with the work.
Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.
Create an account See the product workflow