Because your endpoint is a public URL, you should confirm each webhook really came from Mando before acting on it. Every developer webhook is signed for exactly this.
What each delivery carries
Each delivery includes three headers: an id, a timestamp, and a signature. The signature is an HMAC computed over the id, the timestamp, and the raw body, using your endpoint's signing secret.
How to verify
Get your signing secret from the webhook portal, then on each delivery recompute the signature over the raw body and compare it to the header. Reject a delivery whose timestamp is more than about five minutes from now, to block replays.
The portal shows your secret and ready-made verification code, so use its official webhook library rather than writing the check by hand.
Frequently asked questions
Where is my signing secret?
In the webhook portal, on the endpoint. Reveal and copy it there.
Do I compute over the parsed JSON?
No. Verify over the raw request body exactly as received, before parsing.
Are Slack notifications signed?
No. Only the developer webhook stream is signed. Slack posts use your own Slack workspace.
