Skip to main content
A webhook crosses two systems. Assume that retries, duplicate deliveries, temporary outages, and late responses can occur.

Expected responses

Do not return 2xx if you discarded the event without saving it. Bold will assume that delivery succeeded.

Automatic attempts

Bold attempts to send a notification up to five times. After each failure, it schedules the next attempt with an exponential delay. Each attempt stores the HTTP code, response body, or error message. Query GET /v1/notifications/webhook/{id}/attempts to diagnose it. When you request a manual retry, the notification returns to Pending and is scheduled for immediate delivery.

Consumer rules

  • Process each event idempotently.
  • Save eventId to deduplicate the business event.
  • Save attemptId if you need to audit each delivery.
  • Do not rely on strict ordering between events.
  • Query the API if you need to confirm the final state.
  • Record the original data for auditing and troubleshooting.
  • Verify X-HMAC-Signature before trusting the data.
1

Validate the data received

Check that eventName, majorVersion, minorVersion, and the entity identifier are as expected.
2

Detect duplicates

If you already processed the event, return 2xx without repeating external effects.
3

Queue the work

Save the event in your system and respond promptly.
4

Process in the background

Call management systems, analytics tools, or other services outside the HTTP response period.
If your integration becomes out of sync, use the paginated API to reconcile its state, then resume normal webhook processing.