I will review your API webhook handler for bugs

S
srickey
S
srickey
Rickey

About this gig

I review webhook handler code for bugs, missing event coverage, idempotency gaps, and error-handling issues.


If your app depends on third-party webhook events, a small handler bug can cause duplicate processing, stale user state, missed updates, or inconsistent records.


I can review redacted webhook handler code for issues such as:

missing event branches

weak signature-verification flow

missing idempotency / processed event tracking

unsafe retry behavior

unclear success/failure handling

missing database-state checks

weak logging or audit trail


Important safety policy:

Do not send API keys, webhook secrets, account logins, database passwords, customer passwords, card data, CVC, or private customer information.


I only review redacted code snippets, screenshots, event names, and architecture notes. I do not log into third-party accounts, access payment accounts, modify production systems, or handle sensitive financial information.


You will receive a clear technical review with findings, severity, and recommended next steps.


Get to know Rickey

Rickey

Stripe Billing and SaaS Revenue Operations Auditor

5.0(6)
  • FromUnited States
  • Member sinceJun 2019
  • Last delivery3 years
  • Languages

    English
I help SaaS founders find Stripe billing drift, webhook failures, failed-payment access bugs, and hidden MRR leaks. I audit where payment status, app access, invoices, subscriptions, and webhook handlers fall out of sync. I look for Free Riders, Zombie Subscribers, missing webhook handling, missing idempotency, and evidence gaps. Zero-Write Trust Policy: no unrestricted Stripe secret keys and no write access. If Stripe metadata is needed, I use restricted read-only access through a secure intake path.

My Portfolio