Developer documentation

Webhooks

Verify signatures and handle retries

Authenticate webhook deliveries and make event processing idempotent.

Updated 2026-07-24

Verification sequence

  1. 1Read the raw request body without modifying it.
  2. 2Read the timestamp and signature headers.
  3. 3Reject timestamps outside your accepted tolerance.
  4. 4Compute the expected signature with the subscription secret.
  5. 5Compare signatures using a constant time comparison.

Retries

A webhook may be delivered more than once. Store processed event identifiers before applying nonreversible effects.