POST whose raw body is one CloudEvents 1.0
structured JSON document. Return a 2xx only after the event is durably safe to
acknowledge.
Verify before parsing
Batch Relay uses the Standard Webhooks headers:standardWebhookHeaders component.
Verify the signature over the exact raw request bytes before JSON parsing or
normalization. Do not reconstruct JSON, stringify a parsed object, or substitute
the CloudEvent id for the Standard Webhooks delivery ID.
Dedupe and ordering
Deduplicate by the CloudEvent envelopeid, not by webhook-id. webhook-id
identifies a delivery attempt; id identifies the immutable business event.
Keep a durable record of successfully processed CloudEvent IDs. If an event has
already been processed, safely return a 2xx without repeating its side effect.
For stateful resources, compare resourceversion with the latest version your
integration has applied. Messages can be delayed, retried, or delivered out of
order. A lower resource version must not overwrite newer local state.
Retry-safe processing
- Read the exact raw body.
- Verify Standard Webhooks headers.
- Validate the CloudEvents envelope and topic schema.
- Start a database transaction.
- Record the CloudEvent ID and apply the side effect exactly once.
- Commit, then return a
2xx.
2xx response so delivery can
be retried. Do not return success merely because background work was queued
without a durable handoff.