Which outbound events carry an HMAC signature?
Webhook fan-out signs its JSON body and checks the destination. Direct CRM delivery is a separate Bearer-authenticated path.
Wize has more than one outbound delivery path, so the security claim needs a precise subject. Direct CRM delivery uses a Bearer token. The configurable webhook fan-out is the path that creates an HMAC-SHA256 signature for its event body. Treating those transports as identical would overstate the implementation.
For a matching webhook endpoint, the dispatcher serializes the event, payload and timestamp, signs that exact body with the endpoint secret, and sends the digest in X-Webhook-Signature. It also validates the URL, resolves the host, blocks private, loopback and link-local destinations, pins the accepted address for the request, and applies a timeout.
A receiver still has work to do: recompute the signature over the unmodified body, compare it safely and reject a mismatch. The signature authenticates the webhook fan-out; it is not evidence that every lead transport uses HMAC, nor does it replace TLS, endpoint access control or delivery monitoring.