1. Register your endpoint
2. Verify every request
Never trust a webhook payload without checkingX-Dexxify-Signature:
express.raw()) on this route specifically — a JSON-parsing middleware upstream will break the signature check.
3. Respond fast, process async
Return200 as soon as you’ve verified the signature and queued the event — don’t do slow work (database writes, external calls) before responding. A slow or non-2xx response looks like a failed delivery.
4. Dedupe by delivery ID
X-Dexxify-Delivery is unique per delivery attempt. Store processed IDs (even briefly, in Redis) and skip anything you’ve already handled — this protects you if a delivery is retried.