Prompt
What's the best way to test and debug webhook endpoints locally before production?
Latest observation
The best approach is usually a 3-step workflow: simulate → inspect → replay.
1) Run your webhook endpoint locally
Expose your local server with a tunnel so the provider can reach it:
- ngrok
- Cloudflare Tunnel
- localtunnel
Example with ngrok:
ngrok http 3000
This gives you a public HTTPS URL you can register in the webhook provider.
2) Inspect incoming requests with a webhook tool
Use a request inspector so you can see headers, payloads, retries, and signatures:
- ngrok inspector
- Webhook.site
- RequestBin
- Svix Play / similar webhook testing tools
These help you verify:
- payload shape
- headers
- signature verification
- idempotency behavior
- retry handling
3) Test with real-ish events and replay them
Create a local test harness that:
- sends sample payloads to your endpoint
- includes the same headers/signatures your provider uses
- replays captured requests from logs or inspector tools
If possible, capture a real webhook request in staging and replay it locally.
Best practices for debugging
Validate signature verification
Webhook bugs often come from:
- wrong raw-body handling
- body parsers mutating the payload
- clock skew for timestamped signatures
- using the wrong secret
Make sure your server reads the raw request body before JSON parsing if the provider signs the raw payload.
Return quickly
Respond with 2xx fast, then process asynchronously if needed. This avoids retries while you debug.
Log the right things
Log:
- request ID / event ID
- provider event type
- headers needed for signature checks
- raw body length or hash
- processing outcome
Avoid logging secrets or full sensitive payloads in production.
Simulate retries and failures
Test:
- slow responses
- 500 errors
- malformed JSON
- duplicate deliveries
- out-of-order events
Webhooks are often delivered at least once, so your handler should be idempotent.
A good local testing stack
A strong setup is:
- local server: your app running on
localhost - tunnel: ngrok or Cloudflare Tunnel
- inspector/logging: webhook.site or ngrok inspector
- replay tests: Postman, curl, or automated integration tests
Example manual test:
curl -X POST http://localhost:3000/webhook \
-H "Content-Type: application/json" \
-d '{"type":"test.event","data":{"id":"123"}}'
Recommended development flow
- Build the endpoint locally.
- Test with manual POSTs.
- Expose it via tunnel.
- Register the tunnel URL with the webhook provider.
- Verify signatures and retries.
- Replay captured payloads in automated tests.
- Move to staging before production.
If you want, I can also give you:
- a Node.js, Python, or Go webhook debugging setup
- a signature verification checklist
- a sample local test harness