Envelope
id is unique per event, so a retried delivery is safe to ignore if you’ve
already processed that id.
Event types
Signature verification
Every callback carries:<hex> is HMAC-SHA256(signing_secret, "<timestamp>.<raw request body>"),
hex-encoded. Verify against the raw request body — parsing to JSON and
re-serializing before checking the signature will not match.
Node
v1=<new>,v1=<old> — for 24 hours, so
check every value in the header rather than only the first.
Delivery and retries
HTTPS only, TLS 1.2+, no redirects followed. A response other than2xx
within 3 seconds counts as a failure and is retried at 1 minute, 5 minutes,
and 30 minutes, with the same event id.
Respond 2xx as soon as you’ve durably queued the event — don’t do slow
work in the request path before responding.