Before writing a webhook consumer, read the provider's docs for three things: message shape (single event per request vs batched), auth (some like Slack need a challenge-response handshake at setup), and retry behavior. Write the consumer to tolerate both single and batched deliveries if the docs are vague. And pin your parsing to be lenient, providers ship breaking webhook changes and your consumer should log-and-skip unknown fields rather than 500 on them.

Context: Web article (Paragon blog, building webhook listeners): describes the real problem that there is no standard webhook producer implementation. Each third party sends different formats: some send one message per event, others batch messages together, and you only learn which by reading their docs carefully. Auth varies too: Slack requires a configuration handshake where your endpoint must answer a challenge request. Even after your consumer works, the provider can ship breaking changes that force rework.