Prompt
How do I log webhook requests and responses for debugging?
Latest observation
Oct 5, 2026
OpenAI APIWeb search: off
To log webhook requests and responses for debugging, you usually want to capture both the inbound request your server receives and the outbound response you send back, while being careful not to log secrets or sensitive payloads.
1) Log the incoming webhook request
Record:
- HTTP method
- URL/path
- Headers
- Query params
- Raw body / parsed JSON
- Timestamp
- Source IP
- Request ID / correlation ID
Example in Express (Node.js)
app.post('/webhook', express.json({ verify: rawBodySaver }), (req, res) => {
console.log('Webhook received:', {
method: req.method,
path: req.originalUrl,
headers: req.headers,
body: req.body,
ip: req.ip,
timestamp: new Date().toISOString()
});
res.status(200).json({ ok: true });
});
If you need the raw body for signature verification:
function rawBodySaver(req, res, buf) {
if (buf && buf.length) {
req.rawBody = buf.toString('utf8');
}
}
Then log req.rawBody too.
2) Log the response you send
Capture:
- Status code
- Response body
- Time taken
Example
app.use((req, res, next) => {
const start = Date.now();
const originalSend = res.send;
res.send = function (body) {
console.log('Webhook response:', {
statusCode: res.statusCode,
body,
durationMs: Date.now() - start
});
return originalSend.call(this, body);
};
next();
});
3) Correlate request and response
Generate or reuse a request ID so you can match logs easily:
app.use((req, res, next) => {
req.id = req.headers['x-request-id'] || crypto.randomUUID();
res.setHeader('x-request-id', req.id);
next();
});
Include req.id in all logs.
4) Be careful with secrets and PII
Avoid logging:
- API keys
- Authorization headers
- Signatures
- Passwords
- Personal data
Redact sensitive fields before logging:
function redact(obj) {
const copy = { ...obj };
delete copy.authorization;
delete copy.cookie;
return copy;
}
5) Use structured logging
Instead of plain console.log, use a logger like:
pinowinstonbunyan
This makes searching and filtering much easier.
Example with pino
import pino from 'pino';
const logger = pino();
logger.info({ req }, 'Webhook received');
6) If you’re debugging third-party webhooks
Also log:
- The exact event type
- Delivery ID from the provider
- Retry count
- Signature verification result
- Any parsing errors
If you want, I can show you how to do this in Express, FastAPI, Flask, Django, Laravel, or Spring Boot.