Receive Inbound Webhook
webhooks
Receive Inbound Webhook
Inbound webhook receiver. No Bearer auth — caller authenticates via HMAC signature header (x-causeloop-signature or x-hub-signature-256).
H-1: Buffers raw bytes, resolves the connector’s workspace + inbound webhook, decrypts its signing secret, computes HMAC-SHA256 over the raw body, and FAILS CLOSED — a missing secret, a missing signature header, or a mismatch all 401.
POST
Receive Inbound Webhook