You mean HMAC-SHA’ing the payload with a shared secret?
high-optician-2097
06/21/2023, 2:49 PM
Could you provide the source where this is explained? It would be valuable for us to include in a design proposal if the points apply to Ory’s architecture
We’re also looking to adopt a webhook service that has better monitoring capabilities than we do at the moment! But it’s a bit of work …
l
limited-photographer-61008
06/21/2023, 3:02 PM
Svix has been great so far for us.
p
prehistoric-knife-48976
06/21/2023, 6:49 PM
I found this article from ngrok where they talked about the implementation of web hook security across the industry. For technical details, the wikipedia page I found summed it up pretty well.
h
high-optician-2097
06/22/2023, 8:00 AM
Thanks! I think we can add message authentication to webhooks. Would then simply be another authenticator that can be configured