Webhooks
Verify signatures and handle retries
Authenticate webhook deliveries and make event processing idempotent.
Updated 2026-07-24
Verification sequence
- 1Read the raw request body without modifying it.
- 2Read the timestamp and signature headers.
- 3Reject timestamps outside your accepted tolerance.
- 4Compute the expected signature with the subscription secret.
- 5Compare signatures using a constant time comparison.
Retries
A webhook may be delivered more than once. Store processed event identifiers before applying nonreversible effects.
