Webhooks: Specification
Signed outbound webhooks with HMAC over the raw body, a stable delivery identity, bounded retries into a dead-letter, clock-skew tolerant timestamps, and no secret material in callback URLs.
Inbound payment webhooks acknowledge receipt separately from ledger mutation, deduplicate by provider event identity, reconcile unknown outcomes via provider fetch, and treat the internal ledger as authoritative when ordering or payload conflicts arise.