48-hour launch: 40% off with code LAUNCH40, Guide $5.40 / Kit $11.40

Stripe webhook “Timestamp outside the tolerance zone” — causes and fixes

Stripe libraries reject events whose t= timestamp is more than 300 seconds (5 minutes) from your server's clock. This protects against replay attacks.

  1. Your server clock is wrong. Enable NTP time sync (timedatectl set-ntp true on Linux).
  2. You're re-sending an old saved event with its original header. Trigger a fresh one with stripe trigger payment_intent.succeeded instead.
  3. The request sat in a queue before your code verified it. Verify the signature as soon as the request arrives, then queue the work.

You can pass a larger tolerance (for example constructEvent(body, sig, secret, 600)), but fix the clock first, since a wide window weakens replay protection.

Clock and retry issues aside, the guide covers every common Stripe webhook failure with copy-paste fixes. The kit is a self-hosted Cloudflare Worker relay that verifies Stripe signatures, then retries, replays or dead-letters each event instead of dropping it.

Fix Your Stripe Webhooks guide · Self-Hosted Webhook Relay Kit. Code LAUNCH40 = 40% off until Sun Oct 11, 6:40 AM MT.

Free download: Webhook debugging cheat sheet.

Still failing? Paste your payload, header and secret into the free Stripe signature checker. It runs in your browser and tells you which cause it is.

All five common causes with copy-paste fixes: Fix Your Stripe Webhooks guide ($9). Retries, replay and a dead-letter list in front of your endpoint: the self-hosted relay kit ($19).