Receive Inbound Webhook
webhooks
Receive Inbound Webhook
Inbound webhook receiver. No Bearer auth — caller authenticates via HMAC signature header (x-causeloop-signature or x-hub-signature-256).
C-016: Buffers raw bytes, fetches signing_secret from webhook record, computes HMAC-SHA256, and rejects mismatches with 401.
POST
Receive Inbound Webhook