Prompt
ChatGPT, I need a simple way to receive Stripe and GitHub webhooks, validate them, and forward certain events to internal queues.
Latest observation
Oct 5, 2026
OpenAI APIWeb search: off
A simple, reliable pattern is:
- Expose one small webhook service
- Verify signatures from each provider
- Normalize the event
- Publish only the events you care about to internal queues
Recommended setup
1) Webhook endpoint
Create a single HTTP service with two endpoints:
POST /webhooks/stripePOST /webhooks/github
Keep it minimal:
- read raw request body
- verify provider signature
- parse event
- enqueue internal job/message
- return
2xxfast
2) Signature validation
Stripe
Use Stripe’s signing secret and validate with the raw body and Stripe-Signature header.
Typical flow:
- receive raw payload
- call Stripe signature verification
- if valid, process
event.type
GitHub
Use a shared webhook secret and validate:
X-Hub-Signature-256header- HMAC SHA-256 of the raw body
Reject if signature is missing or invalid.
3) Event filtering
Only forward the events you need.
Examples:
- Stripe:
payment_intent.succeeded,invoice.paid,charge.refunded - GitHub:
push,pull_request,workflow_run
4) Internal queue forwarding
After validation:
- map event to an internal message format
- push to a queue like SQS, RabbitMQ, Redis streams, Kafka, or your job runner
- include:
- provider
- event type
- event id
- timestamp
- raw payload or normalized payload
5) Operational details
Add:
- idempotency/deduplication using Stripe event ID / GitHub delivery ID
- logging of event IDs and verification failures
- retries on queue publish failure
- dead-letter queue for malformed/unhandled events
Minimal architecture
Stripe/GitHub → Webhook API → Verify → Filter → Queue → Internal consumers
Example behavior
Stripe
If event is:
payment_intent.succeeded→ send topayments.queue- otherwise ignore or log
GitHub
If event is:
pushtomain→ send todeployments.queuepull_requestopened → send toreview.queue
Implementation hint
Use a framework that gives access to the raw request body, because signature validation depends on it.
Good choices:
- Node.js: Express/Fastify
- Python: FastAPI/Flask
- Go: net/http
- Rust: Axum/Actix
If you want the simplest possible production approach
Use:
- one webhook microservice
- Stripe SDK for verification
- HMAC verification for GitHub
- SQS or RabbitMQ for queues
- Redis/Postgres for deduplication
If you want, I can provide a working sample in Node.js, Python, or Go with:
- Stripe validation
- GitHub validation
- queue publishing
- event filtering