Verifying webhooks
Verify before you trust, and verify against the raw body.
The SDK is not released. What follows uses plain HTTP.
Every delivery carries a signature. Verify it before you act on the body, compare in constant time, and always compute over the raw request body.
The signed string is the timestamp, the event id, the event type and the raw body, joined by dots in that order. The complete verification function is in the webhook part of the route optimisation guide.