Best practices
Respond quickly; process asynchronously. Return
200 OKas soon as you've verified the signature. Do the heavy lifting in a background worker. Your endpoint must respond within the configured timeout (default 10 s, max 30 s).Deduplicate by event ID. Use
X-Webhook-Event-Id(or the envelopeid) as a unique constraint in your database. Retries are a feature, not a bug — your handler must be safe to invoke twice.Verify every payload. No verification, no processing. Use a constant-time comparison (
crypto.timingSafeEqualin Node.js,hmac.compare_digestin Python,hmac.Equalin Go).Use a valid TLS certificate. Trusted-CA only. Self-signed certificates are rejected at delivery time.
Subscribe narrowly. Only subscribe to the event types your integration uses. Less volume, simpler handler logic, fewer retries.
Watch
developerEmail. Circuit-breaker alerts go to those addresses. Missing them means missing real events.Throttle with
429, not5xx. Returning429withRetry-Afterpauses Jeeves cleanly.5xxburns retry attempts.Stay current on IPs. Update firewall allowlists whenever Jeeves announces an egress-IP change.