Security1 min

Which outbound events carry an HMAC signature?

Webhook fan-out signs its JSON body and checks the destination. Direct CRM delivery is a separate Bearer-authenticated path.

Wize has more than one outbound delivery path, so the security claim needs a precise subject. Direct CRM delivery uses a Bearer token. The configurable webhook fan-out is the path that creates an HMAC-SHA256 signature for its event body. Treating those transports as identical would overstate the implementation.

For a matching webhook endpoint, the dispatcher serializes the event, payload and timestamp, signs that exact body with the endpoint secret, and sends the digest in X-Webhook-Signature. It also validates the URL, resolves the host, blocks private, loopback and link-local destinations, pins the accepted address for the request, and applies a timeout.

A receiver still has work to do: recompute the signature over the unmodified body, compare it safely and reject a mismatch. The signature authenticates the webhook fan-out; it is not evidence that every lead transport uses HMAC, nor does it replace TLS, endpoint access control or delivery monitoring.

Related insights

Which outbound events carry an HMAC signature? | Wize Digital