Webhooks

Verify provider requests from raw bytes, claim events transactionally, enqueue normalized work exactly once, and keep provider parsing outside domain handlers.

Supported approaches

Raw-request verification

available

Verify signatures against untouched request bytes through provider adapters before parsing or trusting payloads.

Packages

@playstack/webhooks

Frameworks and integrations

Transactional receipt claims

available

Claim provider event IDs and enqueue normalized work in one application-owned persistence transaction.

Provider normalization

available

Translate GitHub, Stripe, or custom event envelopes into one stable receipt shape while leaving domain interpretation to consumers.

Frameworks and integrations

integration

Relaypath

Optional Relaypath-backed outbound webhook dispatch without making it a required transport.

framework

Next.js

Compose Playstack server contracts, React bindings, SSR handoff, and route adapters at the Next.js application edge.

framework

NestJS

Connect portable Playstack capabilities to dependency injection, guards, decorators, request context, workers, and lifecycle hooks.

integration

GitHub

Connect OAuth credentials, GitHub App installation tokens, and verified webhook delivery through explicit Playstack boundaries.

integration

Stripe

Create hosted subscription and one-time checkout, then reconcile verified Stripe events into separate billing and payment projections.

integration

Prisma

Persist Playstack capabilities through explicit application-owned Prisma clients, transactions, and managed schema fragments.

integration

BullMQ

Dispatch and process typed Playstack jobs through BullMQ with explicit Redis ownership and native queue access.

integration

Inngest

Dispatch portable Playstack queue jobs through Inngest and serve the generated functions from Next.js, NestJS, or another supported framework.

Package reference

@playstack/webhooks

Preserve the raw request

Signature verification happens before JSON parsing, body transformation, or domain dispatch. Framework adapters must expose the original bytes and normalized headers at this boundary.

ts
import {
  createWebhooks,
  githubWebhookProvider,
} from '@playstack/webhooks'

const webhooks = createWebhooks({
  providers: [githubWebhookProvider({ secret: config.github.webhookSecret })],
  persistence,
  queue,
  clock,
})

const result = await webhooks.receive('github', {
  headers: requestHeaders,
  body: rawBody,
})

Accept once, process safely

The receipt claim and queue handoff use the same transaction kind. A provider retry returns duplicate rather than creating another job, while a rolled-back enqueue leaves the event claim available for the next attempt.

Normalize transport, not business meaning

The provider adapter identifies the provider, event ID, event type, verified payload, and receipt time. Billing, repository automation, delivery feedback, and other consumers remain responsible for interpreting the event under their own policies.

Go

Playstack Pro tag
OriginsPricingBlogNewsletterChangelogStatusRoadmap
ContributorsCommunityIn Use ShowcaseCase StudiesPartnersSponsors
FAQsSupportContact

© 2026 Playstack. All rights reserved.

With OSS
Terms of ServicePrivacy PolicyCookie PolicyImprint

By

Commune Software