Developers
Signed webhooks
Outbound webhooks (for example, CRM lead delivery) are signed so your endpoint can verify a payload actually came from WebOptiva rather than trusting the network alone.
How it works
- X-Weboptiva-Signature holds an HMAC-SHA256 of the raw JSON body, keyed with your webhook secret
- A failing delivery is retried up to 5 times with increasing backoff before it's given up on
Good to know
- Compute the same HMAC-SHA256 over the exact raw request body you received, then compare it to the signature header using a constant-time comparison

