Form Webhooks: Push Responses to Your Own System in Real Time
Instead of exporting a spreadsheet every day, let the form notify your system the moment a response comes in. Here is what a webhook delivers, and the three things you must implement before you trust it.
A webhook means that when something happens (say, a new response is submitted), the form platform sends an HTTP request to a URL you provided. It's the opposite of the usual model, where you have to keep asking, "Is there anything new?"
What you receive
Usually a POST with a JSON body containing the response ID, the submission time, and the value of each field keyed by its field key. The field key is whatever you set in the form builder, so make your keys meaningful (national_id, not q7).
Three things you absolutely must implement
1. Verify the signature
Anyone who knows your webhook URL can send you fake data. The sending platform normally puts a cryptographic signature in a header, computed with a shared secret. You must compute the same signature, compare it, and reject the request if it doesn't match.
Without this, your webhook is an open door.
2. Respond quickly
A webhook endpoint should return 200 within a few seconds. If you have heavy work to do (sending email, updating several systems), return 200 first and then do the work in a background queue.
If you respond too slowly, the sender assumes the delivery failed and sends it again, and you end up processing one response twice.
3. Detect duplicates
Webhooks are delivered "at least once," not "exactly once." That means the same event can arrive twice. Store the response ID, and if you've seen it before, ignore it.
This is the step that usually gets forgotten, right up until the finance system issues the same invoice twice.
Retries and failures
If your server is down, the sending platform will usually retry a few times with increasing delays. But eventually it gives up.
That's why a webhook should never be the only way you receive data. Keep a backup process that, for example, pulls the day's responses from the API every night and reconciles them against what you received.
How to test it in development
Your local server isn't reachable from the internet. There are tools that create a temporary public URL and tunnel it to your local port. For a first look, you can also use services that simply display incoming requests, so you can see the shape of the payload.