# What is a webhook? A webhook is an HTTP request a service sends to your URL when something happens, so your code hears about an event instead of asking for it. **Runtime posts every sandbox, snapshot and volume lifecycle event to your URL, signed with HMAC-SHA256 and retried for about three days, with a delivery log and a test send, at no extra charge.** Both SDKs check the signature in one call and refuse one older than five minutes ([webhooks](/docs/observability#webhooks)). ## Webhooks or polling GitHub's documentation puts the difference simply: webhooks "receive data as it happens, as opposed to polling an API (calling an API intermittently) to see if data is available". Polling many resources also runs into [rate limits](/glossary/api-rate-limit) quickly; a webhook arrives only when there is news. ## What a good webhook sender does | Practice | Why | Runtime | | ----------------------------- | ------------------------------------ | ---------------------------------------------------------- | | Signs each delivery | Anyone can post to your URL | `Runtime-Signature: t=…,v1=…`, HMAC-SHA256 of `{t}.{body}` | | Timestamps the signature | A captured request could be replayed | The SDKs refuse one older than five minutes | | Gives each event an id | Retries mean you may see one twice | `Runtime-Webhook-Id`, the same on every attempt | | Retries failures with backoff | Your endpoint will be down sometimes | Ten attempts over about three days | | Keeps a log you can read | "Did it send?" needs an answer | Deliveries, attempts and status codes, kept 14 days | ## Receiving one Answer with any 2xx within 10 seconds, and do the slow work afterwards. Verify the signature over the raw body, before parsing JSON; a re-serialised body no longer matches. Deliveries are not guaranteed to arrive in order, so order them by `createdAt` ([check the signature](/docs/observability#check-the-signature)). ## Related - [How to receive webhooks](/how-to/receive-webhooks) - [How to verify a webhook signature](/how-to/verify-a-webhook-signature) - [What is an API rate limit?](/glossary/api-rate-limit) - [What is an idempotency key?](/glossary/idempotency-key) ## Sources Checked 27 September 2026. - [About webhooks, GitHub Docs](https://docs.github.com/en/webhooks/about-webhooks) - [Runtime metrics, events and webhooks](/docs/observability)