Webhook signatures authenticate provider messages

A signature on the payload is what lets you tell a genuine delivery from anybody else posting to your endpoint.

Verifying it properly means checking against the raw body, using a constant-time comparison, and rejecting anything unsigned. The common failure is parsing first and verifying afterwards, which means your code has already processed whatever arrived.

More on API security