Glossary
Webhook
Also called: event callback, HTTP callback
A webhook is an HTTP request a system sends to a URL you nominate when an event occurs, so your application is told rather than having to ask. In a document system the events are uploads, versions, approvals, signatures, permission changes and deletions.
Webhook explained
Why push beats polling
Polling a collection endpoint on a timer is slower, consumes rate limit, and scales badly — most requests return nothing. A webhook delivers the event when it happens, which means an approval in the document system can advance a case in another system within seconds.
Idempotency is not optional
Delivery is at-least-once, not exactly-once. Networks fail, receivers time out, and the sender retries — so the same event will arrive twice, and a handler that processes it twice will eventually cause a visible problem. Use the event identifier to detect a repeat.
This is the single most common webhook implementation mistake.
Payload signing
Each payload should carry a signature computed with a shared secret, so the receiver can verify it came from the expected sender and has not been replayed. Without verification, a webhook endpoint is an unauthenticated write path into your system that anyone who learns the URL can use.
Respond fast, process later
Acknowledge receipt immediately and do the work asynchronously. A handler that performs a slow operation before responding causes timeouts, which causes retries, which causes duplicate processing — the failure mode compounds.
Ordering
Event order is not guaranteed across types. Do not infer sequence from arrival order; use timestamps or version numbers in the payload.
FAQ
Webhook: common questions
What if our endpoint is down?
A sender should retry with backoff over a defined window and then stop, ideally alerting you. Check the retry schedule and the failure behaviour before relying on webhooks for anything critical.
Should we subscribe to all events?
No — subscribe narrowly. A handler receiving events it ignores is wasted processing and makes the useful events harder to find when debugging.
Related terms
- Access reviewAn access review is a periodic check that the people who have access to something still need it.
- API keyAn API key authenticates a program rather than a person.
- Break-glass accessBreak-glass access is a deliberate, time-boxed grant of permissions a user does not normally hold, for genuine emergencies.
- Data residencyData residency is the commitment that data is stored and processed within a specified country or region.
- Encryption at restEncryption at rest protects stored data by encrypting it on disk, so that physical access to the storage medium does not yield readable content.
- Permission inheritancePermission inheritance means a document takes its access rights from the folder containing it, rather than being permissioned individually.
Última revisão: 28 de agosto de 2026. Browse the full glossary.