BuildRestAPI — Modern REST API Engineering Logo
BuildRestAPI
← Back to Case Studies
Platform Engineering Teardown

GitHub's REST API: Scaling Millions of Webhooks & Scoped Auth

GitHub handles billions of daily API requests across millions of repositories. Learn how they maintain low latencies using fine-grained PAT tokens, conditional caching, and asynchronous webhook delivery.

1. Conditional HTTP Caching with ETags (304 Not Modified)

GitHub returns a cryptographic ETag header on every read response. When client tools (like CI scripts or pollers) request the resource again with If-None-Match: <etag>, GitHub verifies the hash in cache and returns an empty 304 Not Modified status, saving gigabytes of egress bandwidth.

2. Webhook Security: SHA-256 HMAC Signatures

To prevent spoofing, every webhook payload sent by GitHub includes an X-Hub-Signature-256 header. Consumers compute an HMAC digest over the raw request body using their shared webhook secret. If the digests match using constant-time comparison, the event is authentic.

Quick Jump:
↑ ↓ to navigate↵ to select
BuildRestAPI Search Engine