Glossary · Published 2026-09-29 · AgentiSend team
Webhook signing
Webhook signing: A timestamp and a signature over the raw body, checked before the payload is parsed.
Each delivery signs timestamp.body with the endpoint's signing secret. Compare in constant time, and reject a timestamp outside the signature tolerance. Without the timestamp check a captured delivery can be replayed at you for as long as you keep the secret.
Read the raw body. Parsing and writing the JSON again changes bytes, and the signature then fails at random. A dead end after the retries is a dead letter.
Related terms
- Signature tolerance — How old a webhook timestamp may be before the delivery is rejected as a replay.
- Dead letter — A webhook delivery kept after the retries are used up, so it can be replayed.