Runtime

What is a webhook?

A webhook is an HTTP request a service sends to your URL when something happens, so your code hears about an event instead of asking for it.

Runtime posts every sandbox, snapshot and volume lifecycle event to your URL, signed with HMAC-SHA256 and retried for about three days, with a delivery log and a test send, at no extra charge. Both SDKs check the signature in one call and refuse one older than five minutes (webhooks).

Webhooks or polling

GitHub's documentation puts the difference simply: webhooks "receive data as it happens, as opposed to polling an API (calling an API intermittently) to see if data is available". Polling many resources also runs into rate limits quickly; a webhook arrives only when there is news.

What a good webhook sender does

Practice Why Runtime
Signs each delivery Anyone can post to your URL Runtime-Signature: t=…,v1=…, HMAC-SHA256 of {t}.{body}
Timestamps the signature A captured request could be replayed The SDKs refuse one older than five minutes
Gives each event an id Retries mean you may see one twice Runtime-Webhook-Id, the same on every attempt
Retries failures with backoff Your endpoint will be down sometimes Ten attempts over about three days
Keeps a log you can read "Did it send?" needs an answer Deliveries, attempts and status codes, kept 14 days

Receiving one

Answer with any 2xx within 10 seconds, and do the slow work afterwards. Verify the signature over the raw body, before parsing JSON; a re-serialised body no longer matches. Deliveries are not guaranteed to arrive in order, so order them by createdAt (check the signature).

Sources

Checked 27 September 2026.