Skip to main content
DocumentMS

Glossary

Webhook

Also called: event callback, HTTP callback

A webhook is an HTTP request a system sends to a URL you nominate when an event occurs, so your application is told rather than having to ask. In a document system the events are uploads, versions, approvals, signatures, permission changes and deletions.

Webhook explained

Why push beats polling

Polling a collection endpoint on a timer is slower, consumes rate limit, and scales badly — most requests return nothing. A webhook delivers the event when it happens, which means an approval in the document system can advance a case in another system within seconds.

Idempotency is not optional

Delivery is at-least-once, not exactly-once. Networks fail, receivers time out, and the sender retries — so the same event will arrive twice, and a handler that processes it twice will eventually cause a visible problem. Use the event identifier to detect a repeat.

This is the single most common webhook implementation mistake.

Payload signing

Each payload should carry a signature computed with a shared secret, so the receiver can verify it came from the expected sender and has not been replayed. Without verification, a webhook endpoint is an unauthenticated write path into your system that anyone who learns the URL can use.

Respond fast, process later

Acknowledge receipt immediately and do the work asynchronously. A handler that performs a slow operation before responding causes timeouts, which causes retries, which causes duplicate processing — the failure mode compounds.

Ordering

Event order is not guaranteed across types. Do not infer sequence from arrival order; use timestamps or version numbers in the payload.

FAQ

Webhook: common questions

What if our endpoint is down?

A sender should retry with backoff over a defined window and then stop, ideally alerting you. Check the retry schedule and the failure behaviour before relying on webhooks for anything critical.

Should we subscribe to all events?

No — subscribe narrowly. A handler receiving events it ignores is wasted processing and makes the useful events harder to find when debugging.

A 30-minute session with a solutions engineer, using a folder structure and approval chain that resemble yours — not a generic demonstration tenant.