Webhooks

Verify every delivery event

Postline signs each webhook and limits retries. Consumers must validate freshness, deduplicate event IDs, and tolerate out-of-order delivery.

Signature input

HMAC-SHA256(secret, timestamp + "\0" + event_id + "\0" + body)

Postline-Timestamp: 1784743200
Postline-Event-Id: evt_…
Postline-Signature: v1=…

Receiver requirements

  • Compute the signature from the exact raw request body.
  • Compare signatures in constant time.
  • Reject timestamps outside your allowed window.
  • Store event_id and process each event once.
  • Do not assume events arrive in lifecycle order.

Outbound controls

Endpoint creation requires HTTPS. Private, loopback, link-local, metadata, credential-bearing, and internal targets are blocked and resolved again at dial time. Redirects are not followed. Delivery uses bounded timeouts and retry attempts.