The receiver should verify the documented signed message over the raw request payload and relevant timestamp using its configured webhook secret. Modification of the body before verification can make a valid signature fail. Use constant-time comparisons and prevent replayed events when the integration specifies delivery identifiers.
Developer API · Distribution Hub Glossary
Webhook signature
A cryptographic value that helps a receiving server verify the authenticity and integrity of a webhook.
Key facts
- The raw body can be required for validation
- Webhook secrets are separate from public API output
- Replay handling matters during retries
Explore more in Developer API →
This glossary explains general industry concepts and supported Distribution Hub workflows. Review individual product restrictions, current rates and official API documentation before ordering.