Inbound Webhook Verification
Accept provider events without letting anyone forge them.
What it adds
Signature, timestamp, and replay checks on incoming webhooks, with the real work moved off the request.
What your agent is told to do
6
What your agent is told to do
6-
1
Verify the signature against the exact raw request body, captured before any JSON parsing or middleware rewriting. Re-serialized JSON produces a different signature and every event fails.
-
2
Compare signatures with a constant-time comparison. A byte-by-byte early exit is measurable.
-
3
Reject requests whose signed timestamp is outside a short tolerance window, and record processed event IDs so a replayed event is a no-op.
-
4
Acknowledge with a 2xx as soon as verification passes and process asynchronously. Providers time out fast and retry, so slow handlers manufacture duplicates.
-
5
Support more than one active signing secret so a rotation does not drop events mid-cutover.
-
6
Do NOT trust any data in the payload beyond the event ID. Fetch the current object from the provider's API before acting on it — payloads arrive out of order and may already be stale.
Edge cases it handles
6
Edge cases it handles
6- Events arrive out of order. An update can land before the create. Handle unknown-object events by fetching, not by failing.
- The same event will be delivered more than once. Idempotency is not optional; key on the provider's event ID.
- A malformed or unverifiable body must return an error the provider treats as final, and must be logged with enough context to debug without storing the raw secret.
- Returning a 5xx makes most providers retry with backoff. Return 2xx for events you deliberately ignore, or you will build an accidental retry storm.
- Body-size and content-type limits still apply. An unbounded webhook endpoint is a memory exhaustion vector.
- During secret rotation, verify against both the old and new secret until the old one is retired, then remove it deliberately.
Definition of done
8
Definition of done
8- Signatures are verified against the unmodified raw body using a constant-time comparison.
- Stale timestamps are rejected and repeated event IDs are processed once.
- The endpoint acknowledges within the provider's timeout and processes work in the background.
- Two signing secrets can be valid simultaneously during rotation.
- Ignored events return a success status rather than triggering retries.
- Handlers refetch object state rather than trusting payload contents.
- The feature matches the existing design system.
- No existing functionality is broken.
Related features
Contentful Entry Sync
Contentful Entry Sync
Create and update Contentful entries against the connected space, environment, and locale.
What it does
A sync that writes app records into Contentful entries using the connected space's content model and locale configuration.
How it works
- 1 Have the operator select the space, the environment, and the default locale during connection, and store all three, because writing production content into a sandbox environment is an easy and expensive mistake.
- 2 Fetch the content model at connection time and again before each sync run, map app fields to entry fields by their stable identifiers, and validate the value type against the model before attempting the write.
- 3 Write every localized field under an explicit locale rather than relying on whatever the space treats as default, and state clearly which locales the app owns and which it leaves to editors.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/contentful-entry-sync
Typesense Index Sync
Typesense Index Sync
Keep a search index in step with your records so results stay current and correctly scoped.
What it does
A one-way sync from the app's records into a Typesense collection, with server-enforced tenant filtering and a rebuild path.
How it works
- 1 Identify every model users search today and declare the indexed shape explicitly: the fields people type into, the fields they filter and sort on, and nothing more. Treat a missing or newly added field as absent rather than letting the document fail validation.
- 2 Reuse the app's existing background-job system to push creates, updates, and deletes. Do not index inside the request cycle; a slow or unreachable search service must never make a save fail or hang.
- 3 Build the tenant, workspace, and permission filter on the server at query time and attach it to every search. Do not accept a filter, collection name, or scope value from a client-supplied parameter, because anything the browser can set the browser can change.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/typesense-index-sync
Mapbox Geocoding
Mapbox Geocoding
Convert typed locations into coordinates and structured addresses the app can use.
What it does
Forward and reverse geocoding with confirmed matches, controlled result bias, and coordinate precision rules.
How it works
- 1 Separate the two directions explicitly: text to coordinates for entry and search, coordinates to address for a dropped pin or a device location. They take different inputs, carry different confidence, and fail differently.
- 2 Present ambiguous matches as a list the user confirms. Silently taking the first result is how a record ends up in the wrong country with nobody noticing for months.
- 3 Bias results toward a location only when the app genuinely knows one, such as a workspace address or the map viewport the user is already looking at.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/mapbox-geocoding
How it works
-
1
Copy the link
Grab the Markdown instruction URL for this feature.
-
2
Give it to your AI
Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.
-
3
It inspects, then implements
Your agent reads your existing app first, then adds the feature to fit it.
Works with your stack
These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.
Need it tighter than that? Customize the feature and tell it exactly what you're running.