1. Webhooks
Documentation
  • Back to home
  • StripeKit
  • Installation
  • Getting Started
  • Choosing a Mode
  • Type Reference
  • Setup
    • Configuration
    • Timezones
    • Storage Adapter
    • Money and Currency
    • Error Handling
  • Stripe
    • Elements
  • Modules
    • Overview
    • Customers
      • Overview
      • List
      • Retrieve
      • Find or Create by Email
      • Create
      • Update
      • Sync
      • Delete
    • Payment Methods
      • Overview
      • Create Setup Intent
      • List
      • Attach
      • Detach
      • Set Default
      • Sync
    • Payments
      • Overview
      • Pay With Saved Method
      • Create
      • Retrieve
      • Confirm
      • Cancel
      • Sync
    • Checkout
      • Overview
      • Get
      • Create
      • Submit Fields
      • Apply Coupon
      • Mark Complete
    • Subscriptions
      • Overview
      • Create
      • Retrieve
      • Cancel
      • Resume
      • Toggle Collection Method
      • Update Fields
      • Apply Promotion Code
      • List By Customer
      • Find By Metadata
      • Sync
    • Invoices
      • Overview
      • Retrieve
      • List By Customer
      • List By Subscription
      • Pay With Saved Method
      • Void
      • Finalize
      • Sync
    • Coupons
      • Overview
      • Create
      • Validate
      • Apply To Subscription
      • List
      • Deactivate
    • Webhooks
      • Overview
      • Process
      • Events Reference
    • Sync
      • Overview
  1. Webhooks

Process

$kit->webhooks->process()#

Verifies a raw webhook payload against your webhookSecret, deduplicates it by Stripe event ID, automatically re-syncs the relevant object into your storage adapter, and then calls whichever of your handlers matches the event type.

Signature#

Parameters#

FieldTypeRequiredDescription
payloadstringYesThe raw, unparsed request body. Do not json_decode() it first, Stripe's signature is computed over the exact raw bytes.
signaturestringYesThe value of the Stripe-Signature request header.
handlersarray<string, callable>NoKeyed by handler name, see Events reference for every available key.
autoSyncboolNo, defaults to trueIf false, StripeKit skips its own automatic re-sync step entirely and only calls your handler.

Example request#

Example response#

For an event StripeKit has already processed before (same eventId):
When duplicate is true, no handler is called and no sync happens, StripeKit stops immediately after detecting the event was already seen.

Handler function signature#

Every handler receives two arguments:

Errors#

ExceptionWhen
ConfigurationErrorwebhookSecret was not configured on StripeKit::init().
WebhookVerificationErrorThe signature does not match the payload, meaning the request did not genuinely come from Stripe (or the raw body was altered, for example by JSON-decoding and re-encoding it before calling process()). Return HTTP 400 for this.
Anything your own handler throwsprocess() re-throws whatever your handler throws, after logging it. The event is still marked as processed by that point, so a throwing handler will not cause Stripe to see a duplicate delivery attempt as new.

Notes#

Always pass the raw request body, never a re-encoded one. In most PHP setups this is file_get_contents('php://input'), read before any framework middleware has touched or parsed it.
Return HTTP 200 for every successfully processed event, including duplicates, so Stripe stops retrying delivery. Only return a non-200 status when process() itself throws.
See Events reference for exactly which handler key maps to which Stripe event type, and what StripeKit syncs automatically for each one.
See Storage adapter for what happens to webhook idempotency (hasProcessedWebhookEvent / markWebhookEventProcessed) when no storage adapter is configured.
Previous
Overview
Next
Events Reference
Built with