Agent skill

Podium Webhook Reliability

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Operate a Podium webhook receiver that survives the delivery-side failures — forged events without signature verification, replay attacks against a stateless handler, duplicate processing from…

MITAuto-check passedBackend & APIs

Install Podium Webhook Reliability

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-webhook-reliability -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace podium-webhook-reliability --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/podium-webhook-reliability .claude/skills/podium-webhook-reliability && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
podium-webhook-reliability
GitHub stars
2.8k
Token cost
~4k tokens
SKILL.md length
1,336 words
Files
11 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Operate a Podium webhook receiver that survives the delivery-side failures — forged events without signature verification, replay attacks against a stateless handler, duplicate processing from…

  • Works in 6 steps: HMAC-SHA256 signature verification on… → Replay-attack window (neutralizes… → Idempotent dedup with SET NX EX 86400… → …
  • Building a webhook endpoint for call transcripts
  • SKILL.md covers Overview, Prerequisites, Instructions and Error Handling, plus 3 more sections
  • Runs Python scripts from its folder; calls python3 and uvicorn; needs PODIUM_WEBHOOK_SECRET and SIGNING_SECRET

What it does

Podium Webhook Reliability is an agent skill from jeremylongshore/tons-of-skills-marketplace. Operate a Podium webhook receiver that survives the delivery-side failures — forged events without signature verification, replay attacks against a stateless handler, duplicate processing from Podium's 24h retry policy, lost events with no dead-letter queue, out-of-order batch deliveries, and timing-attack-vulnerable HMAC compares. Use when building a webhook endpoint for call transcripts, webchat events, conversation lifecycle, or review notifications; hardening an existing handler that processes events twice or…

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including scripts and reference files (for example `ARD.md`, `PRD.md` and `config/settings.yaml`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Webhooks. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Building a webhook endpoint for call transcripts
  • Conversation lifecycle
  • Review notifications
  • Hardening an existing handler that processes events twice

Example prompts

  • “podium webhook”
  • “podium hmac”
  • “podium signature”
  • “/podium-webhook-reliability”

Requirements

  • Python 3
  • A credential in SIGNING_SECRET
  • A credential in PODIUM_WEBHOOK_SECRET
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(curl:*), Bash(jq:*), Bash(python3:*), Bash(redis-cli:*), Grep

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. HMAC-SHA256 signature verification on the raw body (neutralizes forgery)
  2. Replay-attack window (neutralizes timestamp replay)
  3. Idempotent dedup with SET NX EX 86400 (neutralizes duplicate processing)
  4. Dead-letter queue before responding 5xx (neutralizes silent event loss)
  5. Batch event ordering by occurred_at (neutralizes reordering)
  6. Constant-time HMAC compare (neutralizes signature-byte timing leak)

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(curl:*)
    • Bash(jq:*)
    • Bash(python3:*)
    • Bash(redis-cli:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • uvicorn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.podium.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PODIUM_WEBHOOK_SECRET
    • SIGNING_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Podium Webhook Reliability loads about 4k tokens when it runs, and up to ~9.7k if it reads all its reference files. Until then it costs about 198 tokens; SKILL.md has 1,336 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~198
When it runs · the whole SKILL.md, loaded when a task matches
~4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 1,336 words, ~4,002 tokens.

Download SKILL.mdSave it as .claude/skills/podium-webhook-reliability/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
podium-webhook-reliability
description
Operate a Podium webhook receiver that survives the delivery-side failures — forged events without signature verification, replay attacks against a stateless handler, duplicate processing from Podium's 24h retry policy, lost events with no dead-letter queue, out-of-order batch deliveries, and timing-attack-vulnerable HMAC compares. Use when building a webhook endpoint for call transcripts, webchat events, conversation lifecycle, or review notifications; hardening an existing handler that processes events twice or drops them silently; or wiring a DLQ + replay path before the on-call rotation starts. Trigger with "podium webhook", "podium hmac", "podium signature", "podium webhook idempotency", "podium webhook replay", "podium dlq", "podium webhook retries".
allowed-tools
Read, Write, Edit, Bash(curl:*), Bash(jq:*), Bash(python3:*), Bash(redis-cli:*), Grep
compatibility
Designed for Claude Code
version
2.12.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
podium, webhooks, hmac, idempotency, dlq, security

Podium Webhook Reliability

Overview

Receive Podium webhooks in production without forged events, double-charged AI side-effects, lost notifications, or out-of-order conversation events. This is not an introductory webhook walkthrough — it is the receiver code your integration runs when Podium retries a 5xx response six times over 24 hours, when a leaked secret lets an attacker POST forged events, when a batch delivery arrives with conversation.deleted ahead of conversation.created, and when on-call needs to drain and replay 800 failed events without re-firing the ones that already succeeded.

The six production failures this skill prevents:

  1. Missing signature verification — a webhook endpoint that accepts any POST will accept forged events. An attacker who learns the URL can create phantom contacts, fire phantom review requests, or impersonate a real customer in a webchat. HMAC-SHA256 over the raw request body is non-optional and must run before any handler logic.
  2. Replay attacks against a stateless handler — a valid signed event POSTed twice (or 1000 times) re-runs every side effect each time. Signature validity alone is not enough — the receiver must reject events whose timestamp falls outside a 5-minute window AND whose nonce has already been seen.
  3. Duplicate event processing from Podium retries — Podium retries webhook delivery on 5xx for up to 24 hours. Without an idempotency cache, every retry re-runs the handler (writes the contact again, fires the review request again, double-charges an AI call). SET NX EX 86400 on the event_id is the cheapest fix that exists.
  4. Lost events without a dead-letter queue — if a handler raises and Podium retries six times and gives up, the event is gone. On-call has nothing to replay. Every handler exception must persist the raw signed payload to a DLQ before the response returns 5xx, so the event is recoverable independent of Podium's retry clock.
  5. Batch event reordering — Podium can deliver multiple events in one POST and ordering across deliveries is not guaranteed. A naive handler processes conversation.deleted before conversation.created and the system observes a delete on a contact that does not exist. Within a batch, sort by occurred_at before dispatch; across batches, gate causally-dependent handlers on the precondition existing.
  6. Timing-attack vulnerability on signature compare — received_sig == computed_sig with == short-circuits on the first byte mismatch. An attacker measures response latency to recover the signature byte-by-byte over a few thousand probes. Always use hmac.compare_digest, which is constant-time over the longer of the two inputs.

Prerequisites

  • Python 3.10+ with fastapi, uvicorn, httpx, and redis (in-memory fallback for dev is provided)
  • Podium account with an OAuth app authorized for webhook delivery: Settings → Developer → Apps → Webhooks
  • The webhook signing secret from the app's Webhooks tab (saved to a secret store — never committed)
  • A receiver URL reachable from Podium (publicly resolvable HTTPS endpoint with valid cert)
  • Redis 6+ for production dedup + DLQ; an in-memory dict + SQLite file fallback exists for dev
  • A podium-auth instance if your handler needs to call back into the Podium API after processing

Instructions

Build in this order. Each section neutralizes one production failure mode.

1. HMAC-SHA256 signature verification on the raw body (neutralizes forgery)

Verify the signature against the raw, unparsed request body. Any framework middleware that JSON-decodes-and-re-encodes before signature check will fail because whitespace and key ordering change. Read the body once, verify, then parse:

python
import hmac, hashlib
from fastapi import FastAPI, Request, HTTPException, Header

app = FastAPI()
SIGNING_SECRET = os.environ["PODIUM_WEBHOOK_SECRET"].encode("utf-8")

@app.post("/webhooks/podium")
async def receive(request: Request, x_podium_signature: str = Header(None)):
    raw = await request.body()              # bytes — DO NOT decode/re-encode
    if not x_podium_signature:
        raise HTTPException(401, "missing X-Podium-Signature")
    if not verify_signature(raw, x_podium_signature):
        raise HTTPException(401, "signature mismatch")
    # ... continue with replay/dedup/dispatch
python
def verify_signature(body: bytes, header_value: str) -> bool:
    # Podium signature header format: "t=<unix_ts>,v1=<hex_hmac>"
    # Adapt to current spec — verify against the Podium developer docs at integration time.
    parts = dict(p.split("=", 1) for p in header_value.split(",") if "=" in p)
    ts, sig = parts.get("t"), parts.get("v1")
    if not ts or not sig:
        return False
    signed_payload = f"{ts}.".encode("utf-8") + body
    expected = hmac.new(SIGNING_SECRET, signed_payload, hashlib.sha256).hexdigest()
    return hmac.compare_digest(expected, sig)    # constant-time, byte-by-byte safe

The t= timestamp is what makes the next mitigation possible. A signature alone with no timestamp is replayable forever.

2. Replay-attack window (neutralizes timestamp replay)

Reject any event whose signed timestamp is more than 5 minutes from now (in either direction — clock skew goes both ways). This bounds the replay window an attacker has even if they capture a valid signed event off the wire:

python
import time

REPLAY_WINDOW_SECONDS = 300        # 5 minutes; tune to your clock-skew tolerance

def within_replay_window(ts_str: str) -> bool:
    try:
        ts = int(ts_str)
    except (TypeError, ValueError):
        return False
    return abs(time.time() - ts) <= REPLAY_WINDOW_SECONDS

Wire within_replay_window(parts["t"]) immediately after signature verification. A failed window check is a 401 — do not return 200, do not enqueue, do not log the body (the attacker is probing).

3. Idempotent dedup with SET NX EX 86400 (neutralizes duplicate processing)

Every Podium webhook carries an event_id (or equivalent unique identifier — verify against the current schema). Reject any event whose event_id is already in the dedup cache. Use Redis SET key value NX EX 86400 so the check and the claim are atomic; 86400 seconds matches Podium's 24-hour retry ceiling:

python
import redis.asyncio as redis

REDIS = redis.from_url(os.environ.get("REDIS_URL", "redis://localhost:6379/0"))

async def claim_event(event_id: str) -> bool:
    # Returns True if this process is the first to see this event_id.
    # Returns False if the event_id is already in the cache (duplicate).
    return await REDIS.set(f"podium:evt:{event_id}", "1", nx=True, ex=86400)

In the handler:

python
event = json.loads(raw)
event_id = event["id"]
if not await claim_event(event_id):
    return {"status": "duplicate", "event_id": event_id}     # 200 — Podium stops retrying

Returning 200 on duplicate is correct — Podium has correctly delivered, the receiver has correctly identified it as already processed. The handler is idempotent by construction.

For dev / smoke environments without Redis, fall back to an in-memory set() with a periodic eviction loop. Documented in references/implementation.md.

4. Dead-letter queue before responding 5xx (neutralizes silent event loss)

Wrap every handler invocation in a try/except. On any exception, persist the raw signed payload plus the timestamp plus the signature to the DLQ before letting the exception bubble. The DLQ entry is the recovery anchor — dlq_replay.py can re-POST it to the handler later:

python
async def safe_dispatch(event: dict, raw: bytes, sig_header: str):
    try:
        await dispatch(event)
    except Exception as e:
        await dlq_persist({
            "event_id": event.get("id"),
            "event_type": event.get("type"),
            "raw_body": raw.decode("utf-8", errors="replace"),
            "signature_header": sig_header,
            "occurred_at": event.get("occurred_at"),
            "received_at": time.time(),
            "exception": f"{type(e).__name__}: {e}",
        })
        raise          # let FastAPI return 5xx; Podium will retry

DLQ backend options (in priority order):

BackendWhen
Redis list LPUSH podium:dlq + scheduled archiver to S3/GCSDefault for prod
SQLite file at /var/lib/podium-dlq.sqliteSingle-node deployments, dev
Append-only JSONL at /var/log/podium-dlq.jsonlFallback when nothing else is available — durable, parseable, ugly

The DLQ is durable independent of the Redis dedup cache. If Redis dies, dedup is degraded but events are still recoverable.

Show full SKILL.md (479 more words)Show less
5. Batch event ordering by occurred_at (neutralizes reordering)

Podium can deliver multiple events in one POST. Within the batch, sort by occurred_at ascending before dispatch. Across batches, do not assume earlier-timestamped events arrived first — guard causally-dependent handlers with an existence check:

python
async def dispatch_batch(events: list[dict]):
    events.sort(key=lambda e: (e.get("occurred_at", 0), e.get("id", "")))
    for event in events:
        await safe_dispatch_one(event)

async def handle_conversation_deleted(event: dict):
    convo_id = event["data"]["conversation_id"]
    # Guard: if the create event hasn't been processed yet, defer this delete.
    if not await convo_exists(convo_id):
        await dlq_persist({
            "reason": "out_of_order_delete_before_create",
            "event_id": event["id"],
            "raw_body": json.dumps(event),
            "received_at": time.time(),
        })
        return
    await delete_conversation_locally(convo_id)

Sorting within a batch is cheap and correct. Cross-batch ordering is undecidable from the receiver side — the DLQ + replay path is the recovery mechanism when out-of-order delivery violates a precondition.

6. Constant-time HMAC compare (neutralizes signature-byte timing leak)

The single most common implementation bug in webhook receivers is received == expected with ==. Python string == short-circuits on the first differing byte; an attacker measures response latency over a few thousand probes and reconstructs the signature byte by byte.

python
# WRONG — leaks signature byte-by-byte via timing
if received_sig == expected_sig:
    return True

# CORRECT — constant-time over the longer of the two inputs
if hmac.compare_digest(received_sig, expected_sig):
    return True

hmac.compare_digest is the only acceptable comparison. The same rule applies to Node (crypto.timingSafeEqual), Go (hmac.Equal), and Rust (subtle::ConstantTimeEq).

Error Handling

HTTP returnedInternal conditionCaller (Podium) behavior
401 UnauthorizedSignature mismatch, missing header, replay window failedPodium does NOT retry — log + audit
400 Bad RequestBody is not parseable JSON post-signature-verifyPodium does NOT retry — investigate Podium-side payload
200 OK (duplicate)event_id already in dedup cachePodium stops retrying — system is idempotent
200 OK (processed)Handler dispatched successfullyPodium stops retrying — normal path
200 OK (deferred)Out-of-order event written to DLQ; will resolve via replayPodium stops retrying — recovery is internal
500 Internal Server ErrorHandler raised; DLQ entry persistedPodium retries with exponential backoff up to 24h
503 Service UnavailableRedis dedup unreachable; handler refusesPodium retries — fail-closed is the safe default

Examples

Verify a captured webhook payload from the command line
bash
# Use the CLI bundled with the skill to verify a captured payload + header against the secret.
python3 scripts/signature_verify.py \
  --body-file /tmp/captured_webhook_body.json \
  --signature-header "t={your-timestamp},v1={your-podium-signature}" \
  --secret-env PODIUM_WEBHOOK_SECRET
# exit 0 = valid; exit 1 = signature mismatch; exit 2 = replay window exceeded
Manually check if an event_id has been seen
bash
python3 scripts/dedup_check.py --event-id evt_{your-event-identifier} --redis-url redis://localhost:6379/0
# exit 0 = first sight (would be processed); exit 1 = duplicate (would be rejected)
Drain the DLQ and replay events through the handler
bash
# After a handler bug is fixed, replay DLQ entries through the receiver.
# The replay path goes through the SAME endpoint as Podium, so signature + dedup still apply.
python3 scripts/dlq_replay.py \
  --target-url https://your-receiver.example.com/webhooks/podium \
  --secret-env PODIUM_WEBHOOK_SECRET \
  --batch-size 25 \
  --rate-per-sec 10

The replay script reuses the original signature header captured at DLQ-persist time — Podium's signing secret is the same secret your replayer uses to compute the header, so no re-signing is required for events captured within the secret's lifetime.

Boot the receiver locally for development
bash
export PODIUM_WEBHOOK_SECRET={your-webhook-secret}
export REDIS_URL=redis://localhost:6379/0   # or unset to use in-memory fallback
uvicorn scripts.webhook_server:app --host 0.0.0.0 --port 8080 --reload

Output

  • FastAPI receiver with HMAC verification on the raw body, replay window, dedup, DLQ, and batch ordering
  • Signature verifier CLI (signature_verify.py) for incident forensics on captured payloads
  • Dedup-cache checker CLI (dedup_check.py) for confirming a specific event was already processed
  • DLQ replayer CLI (dlq_replay.py) for draining persisted failures after a handler fix
  • Redis-backed dedup with 24h TTL aligned to Podium's retry ceiling
  • DLQ persistence with multiple backend options (Redis list, SQLite, JSONL)
  • .gitignore rules covering the webhook secret + captured payload files

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (scripts, references) in skills/.curated/podium-webhook-reliability of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • ARD.md
  • PRD.md
  • config/settings.yaml
  • references/errors.md
  • references/examples.md
  • references/implementation.md
  • scripts/dedup_check.py
  • scripts/dlq_replay.py
  • scripts/signature_verify.py
  • scripts/webhook_server.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Podium Webhook Reliability next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Podium Webhook Reliability compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Podium Webhook Reliability this skilljeremylongshore/tons-of-skills-marketplace2.8k—~4kAutomated safety check: PassMIT
Rls Patternsbybren-llc/safe-agentic-workflow423—~1.5kAutomated safety check: PassMIT
Alert Managementhoangsonww/Claude-Code-Agent-Monitor1.1k—~241Automated safety check: PassMIT
Sec Checkwaynesutton/markdown-site627—~753Automated safety check: PassMIT
Security Threat Modelmajiayu000/spellbook287—~561Automated safety check: PassMIT
Security Threat Modelingdevcodex-labs/devcodex439—~771Automated safety check: PassAGPL-3.0

Similar skills

  • Rls Patterns

    bybren-llc/safe-agentic-workflow

    Row Level Security patterns for database operations. An agent skill from bybren-llc/safe-agentic-workflow.

    423 GitHub stars~1.5k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Alert Management

    hoangsonww/Claude-Code-Agent-Monitor

    Inspect fired CCAM alerts and manage alert rules for token thresholds, event patterns, inactivity, and status duration.

    1.1k GitHub stars~241 tokensUpdated today
    Backend & APIsAuto-check passed
  • Sec Check

    waynesutton/markdown-site

    Security review checklist for Convex functions, auth logic, public queries, admin routes, webhooks, uploads, and AI-generated code.

    627 GitHub stars~753 tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • Security Threat Model

    majiayu000/spellbook

    Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation.

    287 GitHub stars~561 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Security Threat Modeling

    devcodex-labs/devcodex

    安全威胁建模专家 Owner — 当任务涉及权限、认证、授权、输入输出信任边界、密钥策略、审计、攻击面、Webhook/OAuth、敏感操作或用户要求安全专家视角时使用;要求识别滥用路径并绑定缓解验证。

    439 GitHub stars~771 tokensUpdated 23 days ago
    Backend & APIsAuto-check passed
  • Design notification workflows the Novu way — choose channels, set severity, decide when a workflow is critical, configure digests, and route based on subscriber state.

    40k GitHub stars~2.6k tokensUpdated today
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Podium Webhook Reliability

What does Podium Webhook Reliability do?

Operate a Podium webhook receiver that survives the delivery-side failures — forged events without signature verification, replay attacks against a stateless handler, duplicate processing from…. Podium Webhook Reliability is an agent skill from jeremylongshore/tons-of-skills-marketplace. Operate a Podium webhook receiver that survives the delivery-side failures — forged events without signature verification, replay attacks against a stateless handler, duplicate processing from Podium's 24h retry policy, lost events with no dead-letter queue, out-of-order batch deliveries, and timing-attack-vulnerable HMAC compares.

When should I use Podium Webhook Reliability?

Podium Webhook Reliability fits situations like: building a webhook endpoint for call transcripts; conversation lifecycle; review notifications; hardening an existing handler that processes events twice.

How do I install Podium Webhook Reliability in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-webhook-reliability -a claude-code`. Or copy the skill folder (skills/.curated/podium-webhook-reliability in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/podium-webhook-reliability in your project. Claude Code loads it when a task matches its description.

How do I install Podium Webhook Reliability in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-webhook-reliability -a codex`. Or copy the skill folder (skills/.curated/podium-webhook-reliability in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/podium-webhook-reliability in your project. Codex loads it when a task matches its description.

Can I use Podium Webhook Reliability in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-webhook-reliability -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/podium-webhook-reliability, .gemini/skills/podium-webhook-reliability, .github/skills/podium-webhook-reliability and .opencode/skills/podium-webhook-reliability in your project.

What does Podium Webhook Reliability need to run?

Going by SKILL.md and its folder, Podium Webhook Reliability needs Python for the scripts in its folder, the command-line tools its instructions call (python3 and uvicorn) and credentials named PODIUM_WEBHOOK_SECRET and SIGNING_SECRET. Our summary lists: Python 3; A credential in SIGNING_SECRET; A credential in PODIUM_WEBHOOK_SECRET. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(curl:*), Bash(jq:*), Bash(python3:*), Bash(redis-cli:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Podium Webhook Reliability access the network?

SKILL.md names 1 domain. As links in the text: docs.podium.com. This is read from the text; nothing was executed.

Is Podium Webhook Reliability safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Podium Webhook Reliability use?

Podium Webhook Reliability is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Podium Webhook Reliability use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.7k tokens, read only when the agent opens those files.

What are the alternatives to Podium Webhook Reliability?

Skills that share tags, products or a category with Podium Webhook Reliability: Rls Patterns (bybren-llc/safe-agentic-workflow, 423 stars), Alert Management (hoangsonww/Claude-Code-Agent-Monitor, 1.1k stars), Sec Check (waynesutton/markdown-site, 627 stars) and Security Threat Model (majiayu000/spellbook, 287 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Podium Webhook Reliability?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.