Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If a license webhook seems missing, duplicated, or late, first determine whether the provider generated the event, whether it attempted delivery, and whether your application durably processed it. Those are separate stages: a successful HTTP response confirms delivery acceptance, not necessarily that the license change finished. Use the provider’s event history and your own logs to locate the break, then make processing safe to retry.

Start by locating the failure

Trace one license change through three stages: event generation, delivery attempt, and application processing. Record the provider’s event identifier, event type, business object (such as the subscription or license), timestamps, destination URL, HTTP status, and response body. Use the event identifier and business object to correlate provider records with your application logs.

  • No event in provider history: investigate whether the lifecycle transition generated an event, whether the right event type is selected, and whether you are looking at the correct test or live environment.
  • An attempt exists but failed: inspect the attempt’s HTTP response, response body, and timing. Check reachability, TLS or connection failures, timeouts, routing, and signature validation.
  • The provider reports success but access is wrong: inspect your receiver’s acceptance and processing records. A delivery attempt is not proof that downstream license work completed.

Stripe’s troubleshooting guidance starts with the endpoint’s failed attempts and their individual status and response details: Stripe webhook troubleshooting.

Why didn’t my license webhook arrive?

Verify the destination, event selection, and environment

Confirm that the endpoint exists, points to the correct public URL, and subscribes to the event that represents the actual change—creation, update, renewal, expiration, cancellation, or payment failure. Check the provider’s event catalog rather than guessing names. Also confirm that the event was generated in the same environment you are inspecting; test or sandbox activity and live activity may have separate endpoints and histories.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Lemon Squeezy documents license-key and subscription event categories, recommends subscribing to license_key_created when licenses are enabled, and supports event simulation in test mode. Its webhook settings show recent requests and payloads: Lemon Squeezy webhook guide and Lemon Squeezy webhook API documentation.

Check whether the request reached your receiver

If the provider shows an attempt, compare its destination URL, attempt time, status, response code, and response body with web-server and application logs. Verify that the callback accepts the provider’s expected HTTP method and content type and that no proxy, firewall, routing rule, or deployment change blocks it. A missing provider attempt points instead to event generation, subscription filters, destination configuration, or environment mismatch.

Validate signatures against the unmodified body

Use the provider’s signing-secret procedure and verify the signature against the exact raw request body. Middleware that parses or transforms the body before verification can invalidate a legitimate signature. Keep signing secrets out of logs and responses. Lemon Squeezy instructs receivers to validate each request against its signing secret: Lemon Squeezy webhook guide.

Why is the license status still delayed?

Acknowledge only after durable capture

Validate the request, persist it or place it in a durable queue, and then return the provider’s success response. Move slower work—license provisioning, external API calls, email, and other side effects—to a background worker. If the process crashes after returning success but before saving the event, the provider may not retry, leaving your application without a recoverable record.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Lemon Squeezy says non-200 responses trigger retries and recommends retaining event data so it can be processed without waiting for another delivery. Paddle’s current documentation requires a response within five seconds and recommends asynchronous processing. That timing requirement is Paddle-specific, not a universal webhook deadline: Lemon Squeezy webhook guide and Paddle: Handle webhook delivery.

Track receipt separately from completion

Store the event identifier with a processing state such as received, in progress, completed, or failed. If a worker crashes after receipt, allow unfinished work to be retried or recovered; a permanent “seen” marker must not cause an incomplete license change to be discarded. Alert on events that remain unprocessed beyond your operational threshold.

Rank #2
Shelly Pro 3EM 3CT 63 | Wi-Fi & LAN 3-Phase Professional Smart Energy Meter | DIN Rail | Home Automation | Compatible with Alexa & Google Home | iOS Android App | No Hub | Photovoltaic Ready
  • The Shelly Pro 3EM 3CT 63 is a next-gen DIN rail-mountable energy meter for single or three-phase installations, featuring a 63A, 3-phase current transformer for non-contact measurements. It supports 4-quadrant measurement, optical pulse indication of energy usage, and is photovoltaic-ready. *It doesn't have a built-in relay; contactor control requires a Shelly Pro Addon attached to the device.
  • Professional Smart Meter - Shelly Pro 3EM-3CT63 is a professional smart meter that reports accumulated energy, voltage, current, active, and apparent power per phase in real time. It stores data for up to 60 days in 1-minute intervals and includes a real-time clock to maintain accurate time if the SNTP server connection is lost.
  • Ideal for business energy measurement - In commercial buildings, it helps monitor energy usage across floors or departments allowing accurate cost allocation and identification of energy wastage. In manufacturing plants it tracks energy consumption of heavy machinery, optimizing usage to reduce operational costs. For store owners it monitors energy usage of systems like lighting, HVAC § refrigeration, helping to identify inefficiencies § reduce energy bills while supporting sustainable practices
  • Shelly Customer Service - Shelly is one of the fastest-growing Smart Home brands in the world with devices, providing solutions for the automation of private homes, buildings and businesses. We provide our customers with professional support and a 5 years device warranty.
  • Shelly Smart Control App will help you control your Shelly devices remotely and will send notifications for all automated events in your home. You can easily configure devices and manage their settings individually, or you can create personalized scenes by combining Shelly devices to trigger certain actions in your home automation.

Why did I receive the same webhook twice?

Design for duplicate delivery: a provider may retry when it does not receive the expected acknowledgement, and some systems explicitly provide at-least-once delivery. Keep a durable record with a unique constraint on the provider’s stable event identifier. When the same event arrives again, recognize it and return success without issuing another license or repeating a non-idempotent action.

Keep event identity distinct from delivery-attempt identity if the provider exposes both. Use the identifier documented by that provider; Paddle identifies event_id as a deduplication key and documents at-least-once delivery: Paddle: Handle webhook delivery.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do I prevent an older event from overwriting newer license state?

Webhook arrival order may differ from event creation order. Paddle states, “We can’t guarantee the order of delivery for webhooks.” Where your provider supplies a trustworthy event timestamp, compare it with the last applied timestamp before changing state. Paddle recommends occurred_at for ordering; do not assume another provider uses the same field or semantics. If timestamps are absent or ambiguous, fetch the canonical subscription or license state from the provider before applying a potentially stale change: Paddle: Handle webhook delivery.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Retry policies differ by provider

Retry windows and acknowledgement rules are vendor contracts, not general webhook standards. The following figures reflect the providers’ official documentation as verified in 2026; documentation can change, so check the current page for the account and environment you operate.

Provider Documented delivery behavior Recovery controls
Lemon Squeezy Its developer guide says the receiver should return HTTP 200; other status codes trigger up to three more attempts. Official webhook guide. Recent requests, payloads, and resend controls are available in webhook settings. Webhook API documentation.
Paddle Current documentation says a live account can receive up to 60 retry attempts over 3 days and distinguishes sandbox behavior. It also recommends responding within five seconds. Handle webhook delivery. Exhausted notifications can be replayed through its API. The same documentation covers replay and event identifiers. Handle webhook delivery.
Stripe The cited support workflow directs operators to inspect failed endpoint attempts and their response details; a retry maximum or schedule is not established here. Webhook troubleshooting. Inspect endpoint attempts and use Stripe’s currently documented recovery controls; a replay policy is not established here. Webhook troubleshooting.

How to replay a failed event safely

  1. Fix the cause first. Correct the event subscription or destination, connectivity, signature handling, timeout, or processing failure identified in the attempt details.
  2. Use the provider’s supported replay control. Lemon Squeezy provides resend controls in webhook settings; Paddle documents API replay for exhausted notifications. Confirm the current dashboard or API procedure before relying on it.
  3. Verify the full outcome. Confirm the replay receives the expected success response, is recorded by your application, reaches completed processing, and produces the intended license state once. If processing fails after acceptance, recover the stored event through your own queue or retry mechanism rather than assuming the provider will send it again.

For Lemon Squeezy’s request and resend guidance, see its webhook guide and webhook API documentation. Paddle describes notification retries and replay in Handle webhook delivery.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.