Last updated

Best practices

  • Respond quickly; process asynchronously. Return 200 OK as soon as you've verified the signature. Do the heavy lifting in a background worker. Your endpoint must respond within the configured timeout (default 10 s, max 30 s).

  • Deduplicate by event ID. Use X-Webhook-Event-Id (or the envelope id) as a unique constraint in your database. Retries are a feature, not a bug — your handler must be safe to invoke twice.

  • Verify every payload. No verification, no processing. Use a constant-time comparison (crypto.timingSafeEqual in Node.js, hmac.compare_digest in Python, hmac.Equal in Go).

  • Use a valid TLS certificate. Trusted-CA only. Self-signed certificates are rejected at delivery time.

  • Subscribe narrowly. Only subscribe to the event types your integration uses. Less volume, simpler handler logic, fewer retries.

  • Watch developerEmail. Circuit-breaker alerts go to those addresses. Missing them means missing real events.

  • Throttle with 429, not 5xx. Returning 429 with Retry-After pauses Jeeves cleanly. 5xx burns retry attempts.

  • Stay current on IPs. Update firewall allowlists whenever Jeeves announces an egress-IP change.