Skip to content
DocsGo to Dashboard

Developers

Signed webhooks

Outbound webhooks (for example, CRM lead delivery) are signed so your endpoint can verify a payload actually came from WebOptiva rather than trusting the network alone.

How it works

  • X-Weboptiva-Signature holds an HMAC-SHA256 of the raw JSON body, keyed with your webhook secret
  • A failing delivery is retried up to 5 times with increasing backoff before it's given up on

Good to know

  • Compute the same HMAC-SHA256 over the exact raw request body you received, then compare it to the signature header using a constant-time comparison