Webhook Security
Raw-body verification, freshness, and secret rotation.
Require HTTPS, cap the raw request body at 256 KiB, verify all signed fields with timing-safe comparison, reject timestamps outside ±300 seconds, and deduplicate event IDs. Retain old secrets by key ID while old deliveries remain redeliverable.