Agent skill

Webhook Integration

by hashgraph-online in hashgraph-online/awesome-codex-plugins

Dodo Payments webhook handling, covering endpoint setup, Standard Webhooks signature verification on the raw body, payment, subscription, and refund event types, idempotency with webhook-id…

Apache-2.0Auto-check passedBackend & APIs

Install Webhook Integration

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill webhook-integration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins webhook-integration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dodopayments/dodo-agent-plugin/skills/webhook-integration .claude/skills/webhook-integration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
webhook-integration
GitHub stars
1.3k
Token cost
~4.2k tokens
SKILL.md length
811 words
Files
4 (incl. references)
Skills in repo
714
Repo updated
First seen
Licence
Apache-2.0

At a glance

Dodo Payments webhook handling, covering endpoint setup, Standard Webhooks signature verification on the raw body, payment, subscription, and refund event types, idempotency with webhook-id…

  • Works in 2 steps: Create the endpoint in the dashboard → Store the signing secret
  • Receiving Dodo events
  • SKILL.md covers When to use this skill, Core Concepts, Setup: Creating a Webhook… and Webhook Headers and Payload, plus 9 more sections
  • Needs DODO_PAYMENTS_WEBHOOK_KEY and DODO_PAYMENTS_API_KEY

What it does

Webhook Integration is an agent skill from hashgraph-online/awesome-codex-plugins. Dodo Payments webhook handling, covering endpoint setup, Standard Webhooks signature verification on the raw body, payment, subscription, and refund event types, idempotency with webhook-id, retries, and local testing. Use when receiving Dodo events, verifying webhook-signature headers, or syncing your database from payment.succeeded or subscription events.

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/common-mistakes.md`, `references/event-catalog.md` and `references/local-testing.md`).

It sits in Backend & APIs, covering Webhooks. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.

When your agent uses it

  • Receiving Dodo events
  • Verifying webhook-signature headers
  • Syncing your database from payment.succeeded
  • Subscription events

Example prompts

  • “/webhook-integration”

Requirements

  • Python 3
  • A credential in DODO_PAYMENTS_WEBHOOK_KEY
  • A credential in DODO_PAYMENTS_API_KEY

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Create the endpoint in the dashboard
  2. Store the signing secret

What it can do on your machine

Read from SKILL.md and the folder at commit 9e7b281. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript, bash, json, python and go).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.dodopayments.com
    • standardwebhooks.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DODO_PAYMENTS_WEBHOOK_KEY
    • DODO_PAYMENTS_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Webhook Integration loads about 4.2k tokens when it runs, and up to ~7.3k if it reads all its reference files. Until then it costs about 95 tokens; SKILL.md has 811 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 9e7b281, republished under its Apache-2.0 licence (© hashgraph-online). 811 words, ~4,154 tokens.

Download SKILL.mdSave it as .claude/skills/webhook-integration/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
webhook-integration
description
Dodo Payments webhook handling, covering endpoint setup, Standard Webhooks signature verification on the raw body, payment, subscription, and refund event types, idempotency with webhook-id, retries, and local testing. Use when receiving Dodo events, verifying webhook-signature headers, or syncing your database from payment.succeeded or subscription events.

Dodo Payments Webhook Integration

Webhooks deliver real-time notifications when payment events occur. Use them to automate workflows, update databases, send confirmations, and keep your systems in sync.

When to use this skill

  • Setting up a webhook endpoint to receive payment, subscription, or refund events
  • Implementing signature verification to ensure webhook authenticity
  • Handling specific event types (payment succeeded, subscription renewed, etc.)
  • Testing webhooks locally during development
  • Ensuring idempotent webhook processing to handle retries

Core Concepts

Webhook: An HTTP POST request sent by Dodo to your endpoint when an event occurs.

Signature verification: Cryptographic proof that a webhook came from Dodo, not an attacker. Required for production.

Idempotency: Processing the same webhook multiple times produces the same result. Use the webhook-id header to detect and skip duplicates.

Raw body: The exact bytes received from Dodo, before parsing. Required for signature verification.


Setup: Creating a Webhook Endpoint

1. Create the endpoint in the dashboard
  1. Go to Developer → Webhooks
  2. Click Create Webhook
  3. Enter your endpoint URL (must be HTTPS in production)
  4. Select the events you want to receive
  5. Copy the signing secret
2. Store the signing secret
bash
export DODO_PAYMENTS_WEBHOOK_KEY=whsec_...

The SDK reads this automatically. You can also pass it explicitly when initializing the client.


Webhook Headers and Payload

Every webhook request includes three required headers (all lowercase, hyphenated):

HeaderExamplePurpose
webhook-idevt_abc123Unique identifier for this webhook delivery
webhook-signaturev1,base64_signature_hereHMAC-SHA256 signature for verification
webhook-timestamp1704067200Unix timestamp (seconds) when the event was sent

The request body is JSON:

json
{
  "business_id": "bus_xxxxx",
  "type": "payment.succeeded",
  "timestamp": "2024-01-01T12:00:00Z",
  "data": {
    "payload_type": "Payment",
    "payment_id": "pay_xxxxx",
    "status": "succeeded",
    "total_amount": 2999,
    "currency": "USD",
    "customer": {
      "customer_id": "cus_xxxxx",
      "email": "customer@example.com",
      "name": "John Doe"
    }
  }
}

Verification: The Centerpiece

Always verify the signature before processing. Unverified webhooks can be spoofed.

Preferred: SDK helper

The simplest and safest approach. The SDK handles all verification details.

TypeScript/Node:

typescript
import DodoPayments from 'dodopayments';
import express from 'express';

const app = express();
app.use(express.raw({ type: 'application/json' }));

// `environment` is a narrow union, but env vars are `string | undefined`.
// Narrow explicitly rather than casting, and default to test mode so a missing
// variable can never accidentally hit live.
const environment = process.env.DODO_PAYMENTS_ENVIRONMENT === 'live_mode' ? 'live_mode' : 'test_mode';

const client = new DodoPayments({
  bearerToken: process.env.DODO_PAYMENTS_API_KEY,
  environment,
  webhookKey: process.env.DODO_PAYMENTS_WEBHOOK_KEY,
});

app.post('/webhook', async (req, res) => {
  try {
    const unwrapped = client.webhooks.unwrap(req.body.toString(), {
      headers: {
        'webhook-id': req.headers['webhook-id'] as string,
        'webhook-signature': req.headers['webhook-signature'] as string,
        'webhook-timestamp': req.headers['webhook-timestamp'] as string,
      },
    });
    
    // Signature verified. Process the event.
    console.log(`Received ${unwrapped.type}`);
    res.json({ received: true });
  } catch (error) {
    res.status(401).json({ error: 'Invalid signature' });
  }
});

Python:

python
from typing import Literal
from fastapi import FastAPI, Request, HTTPException
from dodopayments import DodoPayments
import os

# `environment` is Literal["live_mode", "test_mode"], not str. Passing the raw
# variable through raises at construction: unset gives
# `ValueError: Unknown environment: None`, and a typo like "test" gives
# `Unknown environment: test`. Narrow it, defaulting to test mode so a
# misconfigured variable can never select live.
ENVIRONMENT: Literal["live_mode", "test_mode"] = (
    "live_mode" if os.getenv("DODO_PAYMENTS_ENVIRONMENT") == "live_mode" else "test_mode"
)

app = FastAPI()
client = DodoPayments(
    bearer_token=os.getenv("DODO_PAYMENTS_API_KEY"),
    environment=ENVIRONMENT,
    webhook_key=os.getenv("DODO_PAYMENTS_WEBHOOK_KEY"),
)

@app.post("/webhook")
async def handle_webhook(request: Request):
    try:
        unwrapped = client.webhooks.unwrap(
            await request.body(),
            headers={
                "webhook-id": request.headers.get("webhook-id", ""),
                "webhook-signature": request.headers.get("webhook-signature", ""),
                "webhook-timestamp": request.headers.get("webhook-timestamp", ""),
            },
        )
        # Signature verified. Process the event.
        return {"received": True}
    except Exception:
        raise HTTPException(status_code=401, detail="Invalid signature")

Go:

go
import (
	"io"
	"net/http"
	"os"

	"github.com/dodopayments/dodopayments-go"
	"github.com/dodopayments/dodopayments-go/option"
)

// The Go SDK has no WithEnvironment(string). It exposes two explicit options,
// so narrow here and default to test mode: an unset or misspelled variable must
// never select live mode.
func dodoEnvironment() option.RequestOption {
	if os.Getenv("DODO_PAYMENTS_ENVIRONMENT") == "live_mode" {
		return option.WithEnvironmentLiveMode()
	}
	return option.WithEnvironmentTestMode()
}

func webhookHandler(w http.ResponseWriter, r *http.Request) {
	client := dodopayments.NewClient(
		option.WithBearerToken(os.Getenv("DODO_PAYMENTS_API_KEY")),
		dodoEnvironment(),
		option.WithWebhookKey(os.Getenv("DODO_PAYMENTS_WEBHOOK_KEY")),
	)

	rawBody, err := io.ReadAll(r.Body)
	if err != nil {
		http.Error(w, "Cannot read body", http.StatusBadRequest)
		return
	}

	// Unwrap takes the raw body and the request headers directly. It is not
	// context-aware and does not take a map: the signature is
	// Unwrap(payload []byte, headers http.Header, opts ...option.RequestOption).
	if _, err := client.Webhooks.Unwrap(rawBody, r.Header); err != nil {
		http.Error(w, "Invalid signature", http.StatusUnauthorized)
		return
	}

	// Signature verified. Process the event.
	w.WriteHeader(http.StatusOK)
}
Alternative: standardwebhooks package

If you prefer manual verification or don't use the Dodo SDK:

typescript
import { Webhook } from "standardwebhooks";
import express from "express";

const app = express();
app.use(express.raw({ type: "application/json" }));

const webhook = new Webhook(process.env.DODO_PAYMENTS_WEBHOOK_KEY);

app.post("/webhooks/dodo", async (req, res) => {
  try {
    const payload = req.body.toString();
    await webhook.verify(payload, req.headers);
    
    const event = JSON.parse(payload);
    console.log(`Received ${event.type}`);
    res.json({ received: true });
  } catch (error) {
    res.status(401).json({ error: "Invalid signature" });
  }
});
unwrap() vs unsafeUnwrap()
  • unwrap() verifies the signature. Use this for all production webhooks.
  • unsafeUnwrap() skips verification. Use only for unsigned test payloads from dodo wh trigger.

Raw Body Requirement

Signature verification requires the exact bytes Dodo sent. If you parse the JSON first and then re-serialize it, the bytes change and verification fails.

Framework-specific setup:

FrameworkRaw body setup
Expressapp.use(express.raw({ type: 'application/json' }))
Next.jsreq.text() in route handlers; no middleware needed
FastifyCustom content-type parser (see adaptor docs)
HonoBuilt-in; no special setup
FastAPIawait request.body() returns bytes
Goio.ReadAll(r.Body)

Webhook Event Catalog

Full guide: references/event-catalog.md.

Covers:

  • Payment events
  • Subscription events
  • Refund events
  • Dispute events
  • License key events
  • Entitlement grant events
  • Credit events
  • Recovery and dunning events
  • Payout events

Production-Grade Handler Pattern

Respond quickly after durably recording the event, process asynchronously, and use idempotency keys. In the worker, insert the idempotency claim and apply all durable business changes in one database transaction. If processing throws, the transaction rolls back the claim so the job can retry safely:

typescript
import DodoPayments from 'dodopayments';
import express from 'express';
import { Queue, Worker } from 'bullmq';

// BullMQ is illustrative; use your preferred durable async queue.

const app = express();
app.use(express.raw({ type: 'application/json' }));

// `environment` is a narrow union, but env vars are `string | undefined`.
// Narrow explicitly rather than casting, and default to test mode so a missing
// variable can never accidentally hit live.
const environment = process.env.DODO_PAYMENTS_ENVIRONMENT === 'live_mode' ? 'live_mode' : 'test_mode';

const client = new DodoPayments({
  bearerToken: process.env.DODO_PAYMENTS_API_KEY,
  environment,
  webhookKey: process.env.DODO_PAYMENTS_WEBHOOK_KEY,
});

type WebhookEvent = ReturnType<typeof client.webhooks.unwrap>;
type WebhookJob = { event: WebhookEvent; webhookId: string };

const connection = {
  host: process.env.REDIS_HOST ?? '127.0.0.1',
  port: Number(process.env.REDIS_PORT ?? '6379'),
};
const eventQueue = new Queue<WebhookJob>('webhook-events', { connection });

app.post('/webhook', async (req, res) => {
  let unwrapped: WebhookEvent;
  
  try {
    unwrapped = client.webhooks.unwrap(req.body.toString(), {
      headers: {
        'webhook-id': req.headers['webhook-id'] as string,
        'webhook-signature': req.headers['webhook-signature'] as string,
        'webhook-timestamp': req.headers['webhook-timestamp'] as string,
      },
    });
  } catch (error) {
    return res.status(401).json({ error: 'Invalid signature' });
  }
  
  // Durably enqueue before acknowledging, keyed by webhook-id for idempotency
  const webhookId = req.headers['webhook-id'] as string;
  try {
    await eventQueue.add(
      `process-${unwrapped.type}`,
      { event: unwrapped, webhookId },
      {
        jobId: webhookId, // Prevents duplicate queue entries
        attempts: 8,
        backoff: { type: 'exponential', delay: 1000 },
      }
    );
    return res.json({ received: true });
  } catch (error) {
    console.error('Failed to persist webhook', error);
    return res.status(503).json({ error: 'Webhook persistence failed' });
  }
});

// Async worker. webhookLog.webhookId must have a unique constraint.
const worker = new Worker<WebhookJob>(
  'webhook-events',
  async (job) => {
    const { event, webhookId } = job.data;

    await db.$transaction(async (tx) => {
      const claim = await tx.webhookLog.createMany({
        data: [{ webhookId, eventType: event.type }],
        skipDuplicates: true,
      });
      if (claim.count === 0) return;

      switch (event.type) {
        case 'payment.succeeded':
          await handlePaymentSucceeded(event.data, tx);
          break;
        case 'subscription.active':
          await handleSubscriptionActive(event.data, tx);
          break;
        // ... handle other events
      }
    });
  },
  { connection }
);

The handlers above must perform entitlement writes through tx. Queue emails or other external work through a transactional outbox; a database transaction cannot roll back an already-sent external request.


Show full SKILL.md (321 more words)Show less

Delivery Semantics

Understand how Dodo delivers webhooks:

PropertyBehavior
Timeout30 seconds for connection and read
SuccessAny 2xx response acknowledges delivery. Return 200 immediately after durably recording the event.
FailureAny non-2xx response triggers a retry.
RetriesEight attempts: immediately, 5s, 5m, 30m, 2h, 5h, 10h, 10h
IdempotencyUse webhook-id to detect and skip duplicates
OrderingNo guarantee. Events can arrive out of order.
Payload freshnessDelivery contains the latest resource state at delivery time
TransportUse HTTPS in production

Framework Adaptor Shortcuts

If you use a supported framework, use the official adaptor package for built-in webhook handling:

FrameworkPackageWebhook handler
Next.js@dodopayments/nextjsWebhooks({ webhookKey, onPayload })
Nuxt@dodopayments/nuxtWebhooks({ webhookKey, onPayload })
Express@dodopayments/expressWebhooks({ webhookKey, onPayload }) - register express.json() first, not express.raw() (it verifies against the parsed req.body)
Fastify@dodopayments/fastifyWebhooks({ webhookKey, onPayload })
Hono@dodopayments/honoWebhooks({ webhookKey, onPayload })
Astro@dodopayments/astroWebhooks({ webhookKey, onPayload })
SvelteKit@dodopayments/sveltekitWebhooks({ webhookKey, onPayload })
Remix@dodopayments/remixWebhooks({ webhookKey, onPayload })
TanStack Start@dodopayments/tanstackWebhooks({ webhookKey, onPayload })
Bun@dodopayments/bunWebhooks({ webhookKey, onPayload })
Better Auth@dodopayments/better-authPlugin with webhooks({ webhookKey, onPayload })
Convex@dodopayments/convexComponent with verified HTTP handler

Next.js example:

The adapter callback does not expose webhook-id, so this payment example uses payment_id as its stable key and commits the claim and durable fulfillment together. Use a handler that exposes webhook-id for event types without a verified stable identifier.

typescript
// app/api/webhook/dodo-payments/route.ts
import { Webhooks } from "@dodopayments/nextjs";

export const POST = Webhooks({
  webhookKey: process.env.DODO_PAYMENTS_WEBHOOK_KEY,
  onPayload: async (payload) => {
    // payload is already verified
    console.log(`Received ${payload.type}`);

    if (payload.type !== 'payment.succeeded') return;

    // webhookLog.webhookId must have a unique constraint. If fulfillment
    // throws, the claim rolls back and Dodo's redelivery can retry it.
    await db.$transaction(async (tx) => {
      const claim = await tx.webhookLog.createMany({
        data: [{
          webhookId: payload.data.payment_id,
          eventType: payload.type,
        }],
        skipDuplicates: true,
      });
      if (claim.count === 0) return;

      await handlePaymentSucceeded(payload.data, tx);
    });
  },
});

Handle subscription.active only in a handler that exposes webhook-id, then commit that claim and the entitlement changes in the same transaction.


Local Testing

Full guide: references/local-testing.md.

Covers:

  • Dashboard test tool
  • CLI: Live forwarding
  • CLI: Unsigned mock events
  • Tunnel

Common Mistakes

Full guide: references/common-mistakes.md.

Covers:

  • Signing anything other than webhook-id.webhook-timestamp.raw_body
  • Re-serializing the parsed body
  • Naive comma-splitting of the signature header
  • timingSafeEqual throwing on length mismatch
  • Granting access from return_url instead of verified webhooks
  • Doing slow work before responding 2xx
  • Acknowledging before durable persistence
  • Committing an idempotency claim before fulfillment

Resources

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in plugins/dodopayments/dodo-agent-plugin/skills/webhook-integration of hashgraph-online/awesome-codex-plugins.

  • SKILL.md
  • references/common-mistakes.md
  • references/event-catalog.md
  • references/local-testing.md

Open the folder on GitHubat commit 9e7b281

Compare with similar skills

Webhook Integration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Webhook Integration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Webhook Integration this skillhashgraph-online/awesome-codex-plugins1.3k—~4.2kAutomated safety check: PassApache-2.0
Novu Design Workflownovuhq/novu40k—~2.6kAutomated safety check: PassCustom licence
Golivemikehasa/golive-skill1.2k—~13kAutomated safety check: NotesMIT
Stripe Appsfossasia/eventyay1.7k1 repos~3.6kAutomated safety check: PassApache-2.0
Dingtalk Messageagentscope-ai/ReMe3.6k—~1.6kAutomated safety check: PassApache-2.0
PR Review Provideryansongda/pay5.4k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Design notification workflows the Novu way — choose channels, set severity, decide when a workflow is critical, configure digests, and route based on subscriber state.

    40k GitHub stars~2.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Golive

    mikehasa/golive-skill

    Take an agent-written app from repo to live production on the user's OWN accounts, with providers they choose (hosting, database, auth, payments, email, domain/DNS).

    1.2k GitHub stars~13k tokensUpdated 6 days ago
    Backend & APIsAuto-check: notes
  • Stripe Apps

    fossasia/eventyay

    A skill your agent uses when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g.

    1.7k GitHub starsUsed in 1 repo~3.6k tokens
    Backend & APIsAuto-check passed
  • Dingtalk Message

    agentscope-ai/ReMe

    钉钉消息发送技能。支持企业内部机器人(批量单聊/群聊)和 Webhook 自定义机器人两种接入方式,支持多机器人管理,支持文本、Markdown、链接、ActionCard、FeedCard等多种消息类型。

    3.6k GitHub stars~1.6k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • PR Review Provider

    yansongda/pay

    A skill your agent uses when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.

    5.4k GitHub stars~2.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Stripe Best Practices

    kanchengw/cnllm

    Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…

    175 GitHub starsUsed in 2 repos~925 tokens
    Backend & APIsAuto-check passed

More from hashgraph-online/awesome-codex-plugins

All 714 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.3k GitHub stars~922 tokensUpdated yesterday
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.3k GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.3k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.3k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Calle

    hashgraph-online/awesome-codex-plugins

    Use CALL-E from Codex through the calle CLI. An agent skill from hashgraph-online/awesome-codex-plugins.

    1.3k GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.3k GitHub stars~618 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Webhook Integration

What does Webhook Integration do?

Dodo Payments webhook handling, covering endpoint setup, Standard Webhooks signature verification on the raw body, payment, subscription, and refund event types, idempotency with webhook-id…. Webhook Integration is an agent skill from hashgraph-online/awesome-codex-plugins. Dodo Payments webhook handling, covering endpoint setup, Standard Webhooks signature verification on the raw body, payment, subscription, and refund event types, idempotency with webhook-id, retries, and local testing.

When should I use Webhook Integration?

Webhook Integration fits situations like: receiving Dodo events; verifying webhook-signature headers; syncing your database from payment.succeeded; subscription events.

How do I install Webhook Integration in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill webhook-integration -a claude-code`. Or copy the skill folder (plugins/dodopayments/dodo-agent-plugin/skills/webhook-integration in hashgraph-online/awesome-codex-plugins) into .claude/skills/webhook-integration in your project. Claude Code loads it when a task matches its description.

How do I install Webhook Integration in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill webhook-integration -a codex`. Or copy the skill folder (plugins/dodopayments/dodo-agent-plugin/skills/webhook-integration in hashgraph-online/awesome-codex-plugins) into .agents/skills/webhook-integration in your project. Codex loads it when a task matches its description.

Can I use Webhook Integration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill webhook-integration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/webhook-integration, .gemini/skills/webhook-integration, .github/skills/webhook-integration and .opencode/skills/webhook-integration in your project.

What does Webhook Integration need to run?

Going by SKILL.md and its folder, Webhook Integration needs credentials named DODO_PAYMENTS_WEBHOOK_KEY and DODO_PAYMENTS_API_KEY. Our summary lists: Python 3; A credential in DODO_PAYMENTS_WEBHOOK_KEY; A credential in DODO_PAYMENTS_API_KEY.

Does Webhook Integration access the network?

SKILL.md names 2 domains. As links in the text: docs.dodopayments.com and standardwebhooks.com. This is read from the text; nothing was executed.

Is Webhook Integration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Webhook Integration use?

Webhook Integration is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Webhook Integration use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.

What are the alternatives to Webhook Integration?

Skills that share tags, products or a category with Webhook Integration: Novu Design Workflow (novuhq/novu, 40k stars), Golive (mikehasa/golive-skill, 1.2k stars), Stripe Apps (fossasia/eventyay, 1.7k stars) and Dingtalk Message (agentscope-ai/ReMe, 3.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Webhook Integration?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,255 GitHub stars. The repository holds 714 skills in this directory. The repository was last updated on October 9, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.