SIEM and Shared Signals
Stripe billing webhook
POST
/webhooks/stripeSigned by Stripe. Subscription and invoice events for billing.
#Authentication
Issuer signature
No bearer credential: the caller proves itself by signing the raw request body. Anything that does not verify is refused (or, on the card rail, declined) before the body is read.
Stripe's stripe-signature header, checked with the billing webhook secret.