Webhook signatures authenticate provider messages
A signature on the payload is what lets you tell a genuine delivery from anybody else posting to your endpoint.
Verifying it properly means checking against the raw body, using a constant-time comparison, and rejecting anything unsigned. The common failure is parsing first and verifying afterwards, which means your code has already processed whatever arrived.
