Webhook Troubleshooting
Signature, raw-body, replay, event-id, and provider response failures.
Verify provider-specific signature inputs without exposing raw payloads.
Use this page for webhook signature failures, raw-body mismatches, replay protection, and provider response diagnostics.
Source boundary
Source boundary: AutoCore current main 7a504f6e430c16d4fcb03ebdea3cc3fb7816df60, checked against immutable v1.0.0-rc.1 at 9edfb109f44cc80385784c694b96392cfc04e70f.
The API retains raw request bytes for signature verification and records idempotency/reconciliation outcomes. Compare provider event identity, timestamp tolerance, signature version, amount, currency, and local state.
| Check | Source-backed expectation |
|---|---|
| Scope | Never disable signature verification or accept a callback manually as a workaround. |
| Evidence | Use placeholders, timestamps, release identity, route, status, and request ID where relevant. |
| Safe action | curl -i -H 'content-type: application/json' https://api.example.invalid/api/v1/payments/webhook |
| Stop condition | Unknown authorization, destructive impact, secret exposure, or conflicting evidence. |
Verification
Run the safe check, record its result, and compare the outcome with the documented contract. If the result depends on external configuration or provider availability, mark it as configuration-dependent rather than claiming a product guarantee.
curl -i -H 'content-type: application/json' https://api.example.invalid/api/v1/payments/webhook
Safety boundary
Examples are non-production and use placeholders. Do not deploy, reset, force a migration, create secrets, activate providers, replay sensitive work, or expose private data from this page.