Turnkey Webhook Playbooks: Zero Glue Code
Most SaaS teams spend weeks writing webhook receiver microservices, provisioning Redis queues, managing Dead Letter Queues (DLQs), and handling duplicate webhook retries. TimesinkDB eliminates this entire architecture. Point your Stripe, GitHub, Shopify, or Clerk webhooks directly at TimesinkDB, and our edge engine verifies HMAC signatures, flattens metrics, and deduplicates deliveries automatically.
Stripe → API Gateway → Lambda Worker → SQS / Kafka → Ingestion Worker → PostgreSQL / DynamoDB.
Requires maintaining 5 cloud resources, handling connection pool spikes, and writing custom deduplication logic.
Stripe / GitHub → https://{region}.timesinkdb.com/databases/{id}/webhooks/{provider}
Zero intermediate lambdas. Edge HMAC validation. Monotonic Last-Write-Wins deduplication. Raw points available for SIMD downsampled queries in <1ms.
Edge HMAC Signature Verification
Webhook security is enforced at the edge before compute execution. When a webhook arrives, TimesinkDB extracts the provider signature header and computes the cryptographic HMAC SHA-256 using your configured webhook secret. Invalid, forged, or expired signatures are rejected immediately with 401 Unauthorized without polluting your time-series storage.
| Provider | Signature Header | Algorithm | Tolerance Window |
|---|---|---|---|
| Stripe | Stripe-Signature |
HMAC-SHA256 (t, v1) | 300 seconds (Replay Defense) |
| GitHub | X-Hub-Signature-256 |
HMAC-SHA256 (sha256=) | Immediate Signature Match |
| Shopify | X-Shopify-Hmac-Sha256 |
HMAC-SHA256 (Base64) | Immediate Signature Match |
| Clerk / Svix | svix-signature |
HMAC-SHA256 (svix-id, svix-timestamp) | 300 seconds (Replay Defense) |
| Custom HMAC | X-Signature / Authorization |
HMAC-SHA256 (Hex or Base64) | Configurable |
Monotonic Deduplication & Replay Immunity
Webhook delivery guarantees from providers are almost exclusively at-least-once. If your server takes 500ms longer to acknowledge an HTTP request, Stripe or GitHub will retry the webhook 3–8 times. In relational databases, this causes duplicate rows, inflated revenue sums, or costly unique index conflicts.
TimesinkDB timestamps incoming points by the provider's authoritative event timestamp (e.g. Stripe's created or GitHub's completed_at). When multiple webhook attempts deliver the exact same event key and timestamp, our storage engine resolves them dynamically via Last-Write-Wins (LWW) during query scans. You get mathematically accurate sums and counts with 0% extra storage overhead and 0% duplicate rows.
Metric vs. Raw Blob Storage Modes
By default, TimesinkDB extracts numeric metrics for fast SIMD aggregation. However, webhook payloads often contain rich customer metadata, line items, and error logs that you may want to inspect later. You can configure the storage mode via query parameter:
Flattens all numeric fields into columnar metric series for instant downsampling. Fixed 16-bytes per point.
Stores the unparsed UTF-8 JSON payload verbatim as an immutable event record. Ideal for full audit logs.
Simultaneously flattens metrics for charting and stores raw JSON for customer debugging under the same timestamp.
1. Stripe Webhooks: MRR & Transaction Velocity
Stream subscription payments, upgrade invoices, and refunds directly into high-speed time-series storage. Never calculate monthly recurring revenue or churn rates by querying heavy PostgreSQL transactional tables again.
Select events: invoice.payment_succeeded, charge.refunded, customer.subscription.deleted.
POST /databases/42/webhooks/stripe HTTP/1.1
Host: fra1.timesinkdb.com
Stripe-Signature: t=1788624900,v1=5257abc98124...
Content-Type: application/json
{
"id": "evt_1MvL322eZvKYlo2C",
"type": "invoice.payment_succeeded",
"created": 1788624900,
"data": {
"object": {
"amount_paid": 4900,
"currency": "usd",
"customer": "cus_9x817a",
"subscription": "sub_84102"
}
}
}
stripe.invoice.payment_succeeded.amount_paid→ 49.00stripe.invoice.payment_succeeded.count→ 1.0
GET /query?seriesKey=stripe.invoice.*.amount_paid&from=-30d&interval=1d&fn=sum
2. GitHub Actions: CI Durations & Failure Rates
Track CI build runtimes, queue latencies, and step failure rates across all repositories in real time. Eliminate heavy third-party CI monitoring SaaS tools with a 1-line webhook configuration.
POST /databases/42/webhooks/github-ci HTTP/1.1
Host: fra1.timesinkdb.com
X-Hub-Signature-256: sha256=d579248b1...
Content-Type: application/json
{
"action": "completed",
"workflow_job": {
"id": 8192031,
"name": "build-and-test",
"conclusion": "success",
"started_at": "2026-09-29T08:10:00Z",
"completed_at": "2026-09-29T08:12:45Z"
}
}
TimesinkDB automatically computes duration differences when start and complete timestamps are present: github.ci.duration_sec = 165.0. Query 95th percentile build durations across PRs in single-digit milliseconds:
GET /query?seriesKey=github.ci.duration_sec&from=-7d&interval=1h&fn=avg
3. Shopify Orders: GMV & Basket Item Velocity
Stream Shopify order creations and fulfillment updates directly to your TimesinkDB cluster. Build live real-time GMV counters and fulfillment latency graphs without putting strain on your storefront application.
POST /databases/42/webhooks/shopify-orders HTTP/1.1
Host: fra1.timesinkdb.com
X-Shopify-Hmac-Sha256: b341fa902...
Content-Type: application/json
{
"id": 512938102,
"created_at": "2026-09-29T08:14:02Z",
"total_price": "149.50",
"currency": "USD",
"line_items": [
{ "title": "Hardware Gateway", "quantity": 1, "price": "149.50" }
]
}
4. Clerk & Auth0: User Signups & Auth Volume
Connect Clerk or Auth0 authentication event streams (via Svix or custom webhooks) to track user onboarding velocity, login peaks, and active session counts.
POST /databases/42/webhooks/clerk-auth HTTP/1.1
Host: fra1.timesinkdb.com
svix-id: msg_2X...
svix-timestamp: 1788624900
svix-signature: v1,g0hM9...
Content-Type: application/json
{
"type": "user.created",
"data": {
"id": "user_2Y8a91b...",
"created_at": 1788624900000
}
}
5. Custom Webhook Playbook (Any Generic Service)
You can integrate webhooks from internal microservices, payment gateways, or cellular IoT dispatchers using standard HMAC SHA-256 signing:
import crypto from "crypto";
const payload = JSON.stringify({
tenant_id: "acme_corp",
active_users: 142,
cpu_pct: 38.4
});
const secret = "whsec_custom_98a72b...";
const signature = crypto.createHmac("sha256", secret).update(payload).digest("hex");
await fetch("https://fra1.timesinkdb.com/databases/42/webhooks/custom-service", {
method: "POST",
headers: {
"X-Signature": `sha256=${signature}`,
"Content-Type": "application/json"
},
body: payload
});