Check the token or trust the call: verifying signature webhooks
· 4 min read
Your product has a new flow: a user signs a mandate inside your app, and the moment the signature is done your backend activates the account, releases the file or moves the deal forward. That moment arrives as a webhook. The decision every integrating developer faces is simple to state: does your handler act on any call that reaches the endpoint, or does it first confirm that the call really came from IgniSign?