Signed, replayable webhooks
Receive tenant events with timestamped HMAC verification, durable event deduplication, secret rotation, delivery history, and operator replay.1
Register a narrow endpoint
Choose only the event types your integration needs and persist the one-time
signing secret in your server secret store.
2
Verify the raw bytes
Read the exact request body once and verify it before parsing JSON. Allow
both the current and previous secret during a controlled rotation window.
3
Deduplicate and acknowledge
Commit your business change and
X-Synapse-Event-Id in one transaction.
Return a 2xx only after both succeed.4
Operate retries
Delivery is at least once and may be reordered. Inspect delivery history,
replay failures after correction, and alert on dead-lettered or aging
deliveries.