Glossary
Webhook signature
A header that proves a webhook came from the service that claims to have sent it and was not changed on the way.
Every Kaabist delivery carries a Kaab-Signature header with a timestamp and an HMAC-SHA256 of the raw body. Verify it on the bytes as received, before parsing; each SDK does it in one call.
example
Kaab-Signature: t=1758362400,v1=5257a869e7ec… webhooks.verify(rawBody, signatureHeader, secret)