Skip to content

Glossary · Published 2026-09-29 · AgentiSend team

Signature tolerance

Signature tolerance: How old a webhook timestamp may be before the delivery is rejected as a replay.

Reject a webhook timestamp more than 5 minutes from now. The webhook signing check is the signature and this window together. A correct signature on an old timestamp is still a replay.

The secret can be rotated. A previous secret stays valid for 24 hours so a delivery already in flight still verifies. After the retries, the delivery is a dead letter.

Related terms

  • Webhook signing — A timestamp and a signature over the raw body, checked before the payload is parsed.
  • Dead letter — A webhook delivery kept after the retries are used up, so it can be replayed.