Registration
Register HTTPS endpoint, event subscription and responsible owner.
DEVELOPER
Deliver partner callbacks with endpoint ownership, signed requests, bounded retry, replay support and idempotent consumption.
Register HTTPS endpoint, event subscription and responsible owner.
Verify signature and timestamp before parsing the event body; rotate signing material through a controlled lifecycle.
Acknowledge quickly, process asynchronously and deduplicate by event identifier.
Expect retries, duplicates and possible out-of-order delivery; replay is an operational action with evidence.
verifySignature(rawBody, signature, timestamp);
if (seen(event.id)) return 204;
enqueue(event); return 204;
Webhook consumers must verify signatures, deduplicate, tolerate retry/out-of-order delivery and keep processing asynchronous before production approval.