Updated Invalid Date 3 min read
Yes - and we sign every payload with HMAC-SHA256 using the secret you set per endpoint. Verify the X-JetSend-Signature header before processing. Signature mismatches are logged and the webhook is considered failed (and will retry) if you return a 401.