AddThisFeature

Webhook Endpoint Management

Let users choose where the app sends events, and which events go there.

involved Developer Experience

What it adds

Creating, editing, and testing outbound webhook endpoints, with destination validation and per-endpoint event subscriptions.

What your agent is told to do

6
  1. 1

    Let users register endpoints with a URL and a chosen set of event types. Default the subscription to nothing — an endpoint that silently receives every event is a data leak waiting to happen.

  2. 2

    Require HTTPS and validate the destination before saving: resolve the host and refuse private, loopback, link-local, and metadata-service addresses.

  3. 3

    Re-resolve and re-check the destination at delivery time, not only at save time. DNS can be repointed at an internal address after validation passes.

  4. 4

    Offer a test delivery that sends a clearly-marked sample event and shows the raw response. Keep test deliveries out of production event history and out of any delivery-success metrics.

  5. 5

    Signing secrets, retries and backoff, per-attempt delivery logs, replay, and auto-disabling repeatedly-failing endpoints are all owned by Webhook Delivery Log and Retry. Extend that feature rather than building a second delivery system here.

  6. 6

    Show the current state of each endpoint — enabled, disabled by the user, or disabled by the system — and link through to its delivery history.

Edge cases it handles

6
  • A redirect can move a validated public URL to a private one. Do not follow redirects on delivery.
  • A URL that resolves to different addresses on each lookup will pass validation once and fail safety later. Check every resolved address, not just the first.
  • Changing an endpoint's subscribed events must not retroactively change what already-queued deliveries contain.
  • Deleting an endpoint with deliveries in flight must stop future attempts without erasing the history someone may be debugging.
  • Two endpoints pointing at the same URL are legitimate — different event sets, different environments. Warn, do not block.
  • Endpoint management is a privileged action. Someone who can add a destination can exfiltrate every event in the workspace, so gate it by role and audit every change.

Definition of done

8
  • Endpoints require HTTPS and are rejected when the destination resolves to a private or link-local address.
  • Destination safety is re-checked at delivery time and redirects are not followed.
  • Each endpoint subscribes to an explicit list of event types, empty by default.
  • Test deliveries are visibly marked and excluded from production delivery history.
  • The endpoint's enabled or disabled state, and who or what disabled it, is visible.
  • Creating, editing, and deleting endpoints is role-gated and audited.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.