Delivery envelope
Webhook bodies identify the event and changed resource. They do not embed the resource’s current state:- Verify the signature against the exact raw body.
- Deduplicate by
eventId. - Route handling by
event. - Use
entityIdto retrieve the resource’s current state when a corresponding GET endpoint is available.
Signature verification
Every delivery includesslash-webhook-signature. Verify its base64 value with
Slash’s public RSA key and SHA-256 over the raw
request body. Do not verify a parsed and re-serialized JSON body.