Websites11 min read

Payment Webhooks: Idempotency, Retries & Security Done Right (2026)

Mohamed Bah·Fondateur, Kolonell
August 15, 2026
Share:
Payment Webhooks: Idempotency, Retries & Security Done Right (2026)

Payment Webhooks: Idempotency, Retries & Security Done Right (2026)

Websites

The verdict in three sentences

A naive webhook handler (no dedupe, no signature check) silently double-ships orders or loses payments: 2 to 8 % of notifications arrive as duplicates. A hardened handler uses an idempotency key, verifies the HMAC signature and responds 200 in under 5 seconds before processing asynchronously. Without these three guardrails, your integration ships twice, mis-books money or opens the door to replay fraud.

Naive vs hardened: the break points

Providers (Paystack, Flutterwave, Wave, Orange Money) resend a webhook multiple times if they don't get a fast 200. Without idempotency, each delivery triggers a new shipment. Without signature verification, anyone who knows your URL can fake a "successful payment." Without a fast response, the provider deems the call failed and retries — worsening duplicates.

PointNaive handlingHardened handling
DeduplicationNoneIdempotency key (event id)
Duplicate deliveries2-8 % unhandledIgnored after 1st
Signature verificationAbsentHMAC mandatory
Response timeProcess then reply (slow)200 < 5 s, process async
Anti-replay windowNoneTimestamp ± 5 min
RiskDouble-ship, fraudControlled

The webhook hardening checklist

A reliable payment webhook ticks six non-negotiable boxes. Each neutralizes a specific class of incident. The golden rule: the webhook confirms the money, never the browser redirect — the user can close the tab, but the webhook still arrives.

GuardrailWhy2026 target
Verify HMAC signatureBlock fake payments100 % of events
Idempotency key (event id)Ignore duplicatesDedupe window 24-72 h
Respond 200 fastAvoid needless retries< 5 s
Process asynchronously (queue)Decouple from providerQueue + workers
Anti-replay window (timestamp)Block replays± 5 min
Backoff on outbound retryDon't hammer the API1 min, 5 min, 30 min, 2 h

Exponential backoff applies when you call the provider back (status check): spacing attempts avoids saturating the API and getting rate-limited.

Mini case study

Fatou runs an online shop in Thiès: 2,000 orders/month, average basket 25,000 FCFA. Her naive integration receives 5 % duplicate webhooks — 100 duplicate events/month. Without idempotency, about 30 % trigger a second shipment — 30 parcels shipped for nothing at ~6,000 FCFA logistics each, i.e. 180,000 FCFA/month lost.

After hardening (idempotency key + HMAC signature), the 100 duplicates are ignored on first delivery. Cost of the work: 450,000 FCFA once. Payback: ~2.5 months, before counting the customer disputes and burned stock avoided.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

FAQ

What percentage of webhooks arrive as duplicates?

As a 2026 order of magnitude, 2 to 8 % depending on provider and network quality. Each unhandled duplicate is a risk of double-shipping or double-booking.

Why respond 200 in under 5 seconds?

Because most providers deem the call failed beyond that and retry the webhook. Responding fast then processing asynchronously stops needless retries.

Is signature verification really mandatory?

Yes, on 100 % of events. Without HMAC, anyone who knows your webhook URL can fake a successful payment and trigger an unpaid shipment.

What dedupe window should I choose?

Between 24 and 72 hours, storing the event id. That comfortably covers provider retries, which usually replay over a few hours.

What retry schedule for my outbound calls?

A typical backoff: 1 min, 5 min, 30 min, 2 h. This growing spacing avoids hammering the provider's API and triggering a rate limit.

Let's talk about your project. We audit and harden your payment webhooks: tested idempotency, signature, retry and anti-replay. WhatsApp +221 77 596 93 33.

Tags:#webhook#idempotence#retry#integration paiement#securite#api#wave#paystack
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.