Webhooks: Implementation and resilience
Inbound provider callbacks are authenticated by HMAC over the raw request body and a timestamp window, with key rotation, rejection of unsigned traffic, and no JSON parse before verification.
Signed outbound webhooks with HMAC over the raw body, a stable delivery identity, bounded retries into a dead-letter, clock-skew tolerant timestamps, and no secret material in callback URLs.