Customer webhooks
Configure authenticated delivery endpoints in Dashboard and verify every signed request before processing it.
Secret handling
Webhook signing secrets are revealed once. Store them as production credentials and rotate them if exposed.
At-least-once delivery
Consumers must deduplicate by event identifier. A successful response acknowledges delivery; failures can be retried.
Bounded handlers
Verify the signature against the raw body, persist the event, respond promptly, and process business work asynchronously.