attio-webhooks-events

v2026.09.24

Build and operate an Attio webhook receiver with raw-body HMAC verification, fast acknowledgement, durable queues, idempotent processing, retry awareness, and reconciliation. Use when implementing or repairing Attio event delivery. Trigger with "Attio webhooks", "Attio events", or "verify Attio signature".

GitHub
安装命令
npx skhub add jeremylongshore/attio-webhooks-events
Markdown
SKILL.md

Attio Webhook Receiver

Overview

This skill implements the complete event-delivery boundary: authenticate the exact payload, acknowledge within Attio's delivery window, process at least once safely, and reconcile missed or delayed effects.

Prerequisites

  • Public HTTPS receiver and approved webhook secret storage
  • Required event types and downstream ownership
  • Durable queue and idempotency store
  • Replay, dead-letter, and reconciliation procedures

Tool Discipline

Use Read, Glob, and Grep to inspect raw-body middleware, route handling, queues, and deduplication. Use WebFetch only for current official Attio webhook documentation. Use Write or Edit after the event contract and failure policy are confirmed.

Current Contract

  • Read Attio-Signature; legacy deliveries may also expose X-Attio-Signature.
  • Compute SHA-256 HMAC over the exact raw UTF-8 request body using the webhook secret and compare hexadecimal signatures safely.
  • Return a 2xx quickly after validation and durable acceptance; Attio documents a 5-second timeout.
  • Delivery is at least once. Use Idempotency-Key for deduplication.
  • Attio documents up to 10 retries over roughly three days and a delivery limit of 25 requests per second per target URL; reverify before rollout.

Authentication

Store the webhook secret server-side. Verify the signature before JSON parsing, logging, queueing, or any state change, and support controlled secret rotation.

Instructions

  1. Capture the raw request bytes before body-parsing middleware transforms them.
  2. Read the supported signature header, decode the expected hex, and reject malformed or unequal-length values.
  3. Compute raw-body HMAC and use a timing-safe equal-length comparison.
  4. Validate the event envelope and reserve Idempotency-Key transactionally.
  5. Persist the event to a durable queue, then return 2xx within the timeout.
  6. Process idempotently with bounded concurrency, explicit dead-letter handling, and redacted telemetry.
  7. Test valid, invalid, duplicate, reordered, delayed, burst, queue-failure, and secret-rotation cases.
  8. Reconcile authoritative Attio state so a missed event cannot create permanent drift.

Approval Boundaries

Do not create production subscriptions, rotate secrets, replay events, or mutate downstream customer state without the responsible owner and rollback controls.

Output

Return the subscription scope, signature evidence, acknowledgement path, idempotency design, queue behavior, failure tests, reconciliation procedure, and owners.

Error Handling

ConditionResponse
Signature is absent or invalidReject without parsing or side effects.
Idempotency key already committedReturn success without repeating work.
Durable queue is unavailableReturn failure so delivery can be retried.
Handler exceeds the timeoutMove work behind the queue and acknowledge earlier.

Examples

Input:

route=/webhooks/attio; events=record updates; queue=durable

Expected handoff:

hmac=raw-body verified; ack=under-timeout; dedupe=transactional; replay=tested

Resources

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

skills/.curated/attio-webhooks-events

默认分支

main

最新提交

e5a6c3b

Tree SHA

c2dc8e8