Verify every delivery event
Postline signs each webhook and limits retries. Consumers must validate freshness, deduplicate event IDs, and tolerate out-of-order delivery.
Signature input
HMAC-SHA256(secret, timestamp + "\0" + event_id + "\0" + body)
Postline-Timestamp: 1784743200
Postline-Event-Id: evt_…
Postline-Signature: v1=…Receiver requirements
- Compute the signature from the exact raw request body.
- Compare signatures in constant time.
- Reject timestamps outside your allowed window.
- Store event_id and process each event once.
- Do not assume events arrive in lifecycle order.
Outbound controls
Endpoint creation requires HTTPS. Private, loopback, link-local, metadata, credential-bearing, and internal targets are blocked and resolved again at dial time. Redirects are not followed. Delivery uses bounded timeouts and retry attempts.