Verify signature
Reject unsigned requests at the edge.
A client-side payload inspector today, a real receiver tomorrow. Paste JSON to validate shape, see keys, and prepare the endpoint contract before exposing a server process.
Waiting for payload...
Reject unsigned requests at the edge.
Store headers, body hash, timestamp, and source.
Use idempotency keys before triggering deploys.