Short answer
Why Is My Webhook Firing Twice?
A webhook can arrive twice because the sender retries after a timeout, multiple subscriptions target the same endpoint, or both test and production workflows are active. Compare event IDs, delivery timestamps, and subscription IDs; acknowledge quickly, then deduplicate processing with the provider event ID.
Common causes
- The receiver responds too slowly, so the sender retries delivery.
- Two webhook subscriptions listen to the same event.
- A proxy or automation relay forwards the same payload more than once.
- The workflow has no idempotency check for event IDs.
Diagnostic steps
- Capture headers, payload event ID, timestamps, and sender delivery logs for both requests.
- List all active subscriptions and workflows pointing at the endpoint.
- Return a successful response quickly and move slow work behind a queue when possible.
- Store each event ID before side effects and skip IDs already processed.
Example
A payment provider times out waiting for a response and retries the same event. Both requests share an event ID, so an idempotency check prevents a second fulfillment.
Caveats
Do not deduplicate only by timestamp or customer email; two legitimate events may share those values. Verify webhook signatures before trusting event IDs.