Guides
Signed outbound webhooks
Tenant-owned endpoints receive versioned events. Verify the HMAC before you trust the body.
Headers: X-Callfora-Signature, X-Callfora-Timestamp, X-Callfora-Event, X-Callfora-Delivery. The signature is sha256=HMAC(secret, timestamp + "." + rawBody). Reject timestamps older than five minutes, then store the delivery id if you need to ignore duplicates.
Verify
const crypto = require("crypto");
const expected = "sha256=" + crypto.createHmac("sha256", secret).update(timestamp + "." + rawBody).digest("hex");Failed deliveries retry with backoff. Replay a delivery from Integration Hub. Rotate the signing secret there; the previous secret stops signing new jobs immediately.