Robust Webhook Verification (HMAC + Timestamp)

2141
0

Webhooks are a security boundary. Verify signatures with constant-time compare, include a timestamp window to prevent replay, and store processed event IDs to make handlers idempotent.