Danger Casey

Camp Counselor

Webhooks: Lessons (Un)learned

Event Logo

Tuesday, January 17, 2023 - 8:30 PM UTC, for 1 hour.

Regular, 60 minute presentation

Room: Campsite 2

webhooks
apis
security
design antipatterns
design patterns

Webhooks are a pillar of modern application development. They notify us of that new commit, an incoming text message, our email was delivered, and a payment was processed. Our systems can’t function without webhooks sending data seamlessly and securely across the internet. But what happens if they’re not secure? What happens if your webhooks are intercepted, manipulated, or even replayed against your systems? What are the best ways - as both a provider and consumer - to protect our systems? In this session, we’ll delve into the 100+ implementations we explored to build webhooks.fyi to identify the best and worst patterns to protect our systems now and in the future.

Prerequisites

Familiarity with a major API provider like Stripe, Twilio, Github, Slack, etc

favorited by:
Mandy Hubbard Noah Jenkins Cori Drew Brad Garropy Clark Sell Sharon Cichelli Danger Casey Caleb Jenkins Peter Ritchie Brian Morrison II Arana Fireheart Allen Zaudtke Colleen Dunlap Robert Derman