From Ping to Mention

Pingback arrived in 2002 as a clever idea: when one blog linked to another, the linking site could automatically notify the target. The mechanism was XML-RPC, a dense remote-procedure-call protocol, and that decision proved fatal. XML-RPC's complexity made Pingback a spam vector almost immediately — automated bots flooded blogs with fake notifications, and many site owners ended up switching Pingback off themselves just to stay functional.

Webmention, a W3C-standardised protocol developed through the IndieWeb community and co-authored by Martijn van der Ven and Tantek Çelik among others, solves the same problem with a dramatically simpler mechanism. When Site A publishes a post that links to Site B, Site A's software sends a plain HTTP POST request to Site B's webmention endpoint — a URL advertised in the target page's headers or <link> element. Site B then fetches Site A's page to verify the link actually exists before accepting the mention. That verification step is the key difference: Pingback did specify a source check, but it was inconsistently implemented, and its XML-RPC endpoints were widely abused for spam and DDoS amplification. Webmention's source-check means a fake notification fails on inspection.

Small self-hosted server on a home-office shelf with ethernet cables routed neatly, indicator lights lit
Miniflux and FreshRSS will run on hardware of this order. That is the whole argument for hosting a reader yourself.Photo: panumas nikhomkhai / Pexels
Terminal window on a dark monitor showing a raw Atom feed in XML, angle brackets and namespaces visible, person's hands on keyboard
A feed is a text file sitting on a server. Between the publisher and the reader there is a fetch, and nothing else.Photo: Tima Miroshnichenko / Pexels

The notification carries almost no data — just the source URL and the target URL. What the receiving site does with that is entirely its own business. A blog might display the mention as a comment, a like, or a repost, depending on the microformats2 markup it finds when it fetches the source. A news site might simply log inbound links. The protocol specifies only the handshake; the presentation is left to the publisher.

Support is real but uneven. WordPress has a Webmention plugin maintained by the IndieWeb community. Ghost, Micro.blog, and a number of static-site setups support sending or receiving mentions. Bridgy, a widely used IndieWeb service, translates social-media responses — Mastodon boosts, for instance — into webmentions that a site's endpoint can receive. The Fediverse's native protocol, ActivityPub, handles its own notification layer, but Bridgy makes the two worlds talk.

For publishers who care about owning their conversation layer rather than surrendering it to a platform's comment box, Webmention is the most functional version of that idea the open web has produced.

From the record

How the handshake works

  • Site A publishes a post with a link to Site B
  • Site A sends an HTTP POST to Site B's webmention endpoint (source URL + target URL only)
  • Site B fetches Site A's page to verify the link is present
  • Verification passes → mention is accepted; no live link found → mention is rejected