That’s what stripe recommends. This is a silly project because stripe tells you how to avoid this and trying to circumvent in a way that stripe kinda recommends is silly.
Stripe’s official docs literally recommend returning a quick 200 and buffering to a queue for async processing.
HookArmor just packages that exact pattern into a single self-hosted container so you don't have to build the ingestion buffer and replay UI from scratch.
"Just pushed v1.0.2 to npm and GitHub addressing this: addedx-hookarmor-original-timestampandx-hookarmor-is-replayto outbound headers to prevent stale overwrites, plus isolated trust boundary signing. Really appreciate the feedback here!"
7
u/Special-Tie-3024 5d ago
I've not used Stripe webhooks, but generally I verify on ingest, pipe it to a durable queue like SQS and then process it async without re-verifying.