Webhooks and security
The SDK verifies the signature, timestamp, and nonce against the raw request body before applying a command. Configure the previous secret explicitly during rotation.
x-acp-signatureHex HMAC-SHA256 digest.
x-acp-timestampUnix seconds; rejected beyond 300s drift.
x-acp-nonceSingle use; a repeat is rejected.
Receiver checklist
- Sign over the exact string
timestamp + "." + nonce + "." + body. - Reject a missing header, a stale timestamp, or a seen nonce with
403. - Accept both
ACP_WEBHOOK_SECRETandACP_WEBHOOK_SECRET_PREVduring an overlapping rotation window. - Return quickly. The dispatcher retries, so make the handler idempotent by
command_id.