CtrlK
BlogDocsLog inGet started
Tessl Logo

checkout-com-webhooks

Receive and verify Checkout.com webhooks (checkout.com — the global payments processor: card acquiring, APMs, disputes, payouts, issuing). Use when setting up a Checkout.com webhook handler, debugging Cko-Signature verification, or handling events like payment_approved, payment_captured, payment_declined, payment_refunded, dispute_received or fraud_reported. Checkout.com signs with HMAC-SHA256 over the RAW body, hex-encoded, in the Cko-Signature header, and can optionally send a static Authorization header key. Not Checkout Page (checkoutpage.com), not CheckoutJoy, not 2Checkout / Verifone, not Stripe Checkout, not Shopify checkout webhooks.

73

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, expert-aimed reference: executable fail-closed verification code, precise gotchas that reflect real failure modes, and well-organized references that exist and deliver what they promise. Weak spots are limited to padding (Related Skills list, attribution, repeated disambiguation) and references to examples/ directories that are not present in the bundle.

Suggestions

Trim the 13-item Related Skills list to the 2-3 most relevant (e.g., webhook-handler-patterns, stripe-webhooks, adyen-webhooks) and move the rest to a reference file or drop the Attribution section — these add ~40 lines of low-value tokens.

Fix or remove the examples/express/, examples/nextjs/, and examples/fastapi/ links — no examples/ directory exists in the bundle, so following them fails; either include the examples or inline a minimal complete handler.

Add an explicit numbered handler checklist (verify → parse → dedupe on evt id → enqueue → 2xx within 10s) with a 'if verification fails, respond 401 and check the top causes' recovery step, rather than delegating failure recovery entirely to references/verification.md.

DimensionReasoningScore

Conciseness

The body is dense and expert-level — it assumes knowledge of HMAC, webhooks, and Node crypto, and never explains background concepts — but a few sections pad the token budget: the 13-item Related Skills list, the Attribution section, and the disambiguation note repeated verbatim from the description. These are minor trims, matching the "efficient; minor instances of over-explanation" anchor rather than the lean 5.

4 / 5

Actionability

The core verification code is complete, copy-paste ready, and fail-closed (length guard before timingSafeEqual, missing-header check), with a real example key value, exact retry schedule (8 attempts with intervals), a runnable local-dev command (`npx hookdeck-cli listen 3000 ...`), and an explicit "verify, enqueue, return 2xx" guidance line. This matches the fully-executable anchor covering the common cases.

5 / 5

Workflow Clarity

The handler sequence is clearly laid out (set signature key → verify raw-body HMAC → optionally check Authorization → dedupe on evt id → ack within 10s) with validation behavior embedded in the code (fail closed, length guard) and explicit error consequences ("uncaught throw becomes a 500, which Checkout.com retries eight times"). It falls short of the 5 anchor because there is no explicit ordered checklist or debug-on-failure loop in the body itself — recovery guidance is delegated to references/verification.md.

4 / 5

Progressive Disclosure

Structure is good: three one-level-deep reference files (overview.md, setup.md, verification.md) are well-signaled with per-file content summaries, and all three exist in the bundle with matching content. The gap against the 5 anchor is the "For complete handlers with tests, see examples/express/, examples/nextjs/, examples/fastapi/" pointers — no examples/ directory exists in the bundle, so those references are broken.

4 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is a model example: explicit what-and-when, concrete event and header trigger terms, the signing scheme spelled out, and aggressive disambiguation against the five most confusable lookalikes. Third-person voice throughout; no fluff despite its density.

DimensionReasoningScore

Specificity

Concrete actions are explicitly named — "Receive and verify Checkout.com webhooks", "debugging Cko-Signature verification", "handling events like payment_approved, payment_captured, payment_declined, payment_refunded, dispute_received or fraud_reported" — plus the exact verification mechanism ("HMAC-SHA256 over the RAW body, hex-encoded, in the Cko-Signature header"). Coverage is comprehensive, matching the anchor for multiple specific concrete actions; nothing is vague or generic.

5 / 5

Completeness

The description answers "what" explicitly ("Receive and verify Checkout.com webhooks ... signs with HMAC-SHA256 over the RAW body, hex-encoded ... optionally send a static Authorization header key") and "when" with a concrete "Use when" clause listing three trigger scenarios. This matches the anchor that clearly and explicitly answers both what AND when with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural user phrasing is thoroughly covered: "setting up a Checkout.com webhook handler", "webhook handler", "Cko-Signature verification", "payment_approved / payment_captured / payment_refunded / dispute_received" — the exact event names and header names a user would type. Domain URL (checkout.com) and command-style phrases are present; no common synonyms missing.

5 / 5

Distinctiveness Conflict Risk

It hardens the niche with explicit exclusions — "Not Checkout Page (checkoutpage.com), not CheckoutJoy, not 2Checkout / Verifone, not Stripe Checkout, not Shopify checkout webhooks" — alongside the exact provider identity and header/event vocabulary. Conflict risk with similarly-named skills is minimal, matching the clear-niche anchor.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.