Aglet

Learn from webhook endpoint redirects

The durable lesson is a destination contract covering host, path, method, body, signature, and receipt. Preserve the redirect or rewrite that exposed the issue. Document migration ownership and sender limits instead of treating a final response as proof of safe delivery.

Keep the lesson for the next incident

  1. Document destination rules

    Record canonical URL, environment, redirect policy, proxy ownership, method and body preservation, signature input, receipt, migration, rollback, and unapproved-target disposition. Specify whether a changed destination is permitted to receive the original payload and which component enforces that destination rule.

  2. Keep route fixtures

    Retain direct, reviewed redirect, path rewrite, method change, invalid target, signature, duplicate, and migration cases with synthetic events. Store expected request and receipt state. Include the original redirect shape. Retain the receiver response and signed request representation for the redirected case, so migration cannot conceal a changed verification input.

  3. Review endpoint changes

    Watch URL configuration, redirect statuses, target changes, missing receipts, signature failures, and duplicate attempts by endpoint. Assign an owner and threshold. Close the follow-up only when every configured destination has route coverage.

What to carry forward

Close learning with destination rules, route fixtures, migration ownership, and redirect signals. Keep sender behavior visible. The useful outcome is an explicit canonical endpoint and a safe response to any unexpected hop. After a rollback, compare the active canonical destination with the sender configuration and remove any assumption that both changed together.

Technical background: Stripe documentation.

Keep the decision with the work.

Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.

Create an account See the product workflow