Skip to content

SIEM and Shared Signals

Stripe billing webhook

POST/webhooks/stripe

Signed by Stripe. Subscription and invoice events for billing.

#Authentication

Issuer signature

No bearer credential: the caller proves itself by signing the raw request body. Anything that does not verify is refused (or, on the card rail, declined) before the body is read.

Stripe's stripe-signature header, checked with the billing webhook secret.