How to configure and debug a payment webhook
A payment can succeed on the bank's side without the order being validated on the store's side, if the webhook responsible for confirming the transaction never reaches the site. It's one of the most common causes of orders stuck pending despite a payment that actually went through.
Why the webhook exists alongside the customer redirect
After paying, a customer is redirected from the payment gateway back to the merchant site: this is known as the customer redirect. In theory, this redirect is enough to validate the order, but it isn't a hundred percent reliable, because the customer can close their browser, lose their connection, or simply never come back to the site after paying.
The webhook solves this by taking a different path, independent of the customer's browser: the payment gateway contacts the site's server directly, in the background, to confirm that the payment actually went through. This mechanism, not the customer redirect, is what should be treated as the source of truth for definitively validating an order.
Checking that a webhook is actually working
-
Check the URL configured on the gateway side
The payment gateway's admin console (Stripe, PayPal or another) lists the address configured to receive webhooks; it must match exactly the one expected by the module or extension installed on the site.
-
Check that this address is publicly accessible
The URL must be reachable from the outside without prior authentication; a site still protected by a global password or in maintenance mode systematically blocks webhook delivery.
-
Check the delivery log on the gateway side
Most payment gateways show a history of webhook delivery attempts, along with the HTTP response code returned by the site, which immediately shows whether the problem lies with the site or the gateway.
-
Check the site's logs
On PrestaShop or WooCommerce, the logs for the relevant payment module show whether the request was received and correctly interpreted.
-
Test with a real, low-value payment
A real-world test remains the most reliable way to confirm that the whole chain works, from payment through to automatic order validation.
Common mistakes
- Confusing the customer redirect with the webhook, assuming the post-payment redirect is enough to reliably validate the order.
- Leaving the site in maintenance mode or password-protected during a webhook test, which blocks delivery without anything clearly signalling it on the customer's side.
- Changing the API key or merchant account without updating the webhook URL or configuration on the new setup.
- Ignoring failed attempts visible on the gateway side, when they show precisely since when and why automatic validation has stopped working.
- Blocking the gateway's requests with a firewall or an overly strict security plugin, which sometimes filters automated requests without distinguishing a legitimate webhook from an unwanted bot.
Frequently asked questions
An order stays pending even though the customer has paid, what should you do right away?
Do you need special technical access to configure a webhook?
Can a webhook be received twice?
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.