Payment and partner callbacks: keeping critical notifications reachable
Use signature verification, duplicate handling and narrowly scoped exceptions for callbacks.
Contents of this article
Callbacks do not behave like browsers
Payment, logistics and partner webhooks are server-to-server calls and may not execute scripts or carry browser cookies. Interactive challenges can break them. Inventory these endpoints and validate with each partner.
A narrow exception does not remove authentication
Scope exceptions to the required host, path, method and verified partner conditions. The application must still validate signatures, timing and business objects; source IP alone is not proof of message authenticity.
Design for retries and duplicates
Partners may retry when the expected response is missing. Persist processing results and detect duplicates to avoid repeated fulfillment or accounting. Reliable asynchronous work still needs explicit retry and consistency handling.
Validate failure branches
Use partner test facilities for valid callbacks, invalid signatures, timeouts and duplicates. Correlate edge and application records to locate failures before changing the smallest necessary policy scope.
References
OWASP REST Security Cheat Sheet
