Free tools Windows power users keep installed
One-click scans. No signup required.
If a webhook provider does not sign its requests, treat every delivery as untrusted input. First check whether the provider supports a signature or another authentication method you can verify. If it does not, do not let the request alone authorize a payment, account change, access grant, or destructive action. For high-impact events, verify the current state through a separately authenticated API—or decline the integration if the remaining risk is unacceptable.
First, confirm what “does not sign” means
Check the provider’s current documentation and configuration. A signing secret or signature header may be optional, or the provider may support a different authenticated mechanism, such as mutual TLS or an authorization token. Confirm what your receiver is expected to validate; a header name or secret-looking URL is not proof that the request body is authenticated.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
APIs and Webhooks for Beginners: Connect Apps, Automate Tasks, and Build Useful Integrations | $2.99 | Buy on Amazon |
| 2 |
|
Shelly Pro 3EM 3CT 63 Wi-Fi & LAN 3-Phase Smart Energy Meter | $150.99 | Buy on Amazon |
For example, GitHub’s webhook guidance describes a shared secret and HMAC signature, and its example rejects a request when the signature header is missing. That illustrates an important rule: if your endpoint is configured to require signatures, a missing signature must fail verification rather than silently falling back to acceptance.
Ask for a supported authentication method
Ask the provider whether it offers a documented request-signing scheme or another mechanism your receiver can reliably validate. Mutual TLS and authorization tokens are possible controls discussed in the OWASP Cheat Sheet Series draft, but the exact implementation and verification steps depend on the provider. Do not assume a mechanism is supported—or that it authenticates the message body—without checking the provider’s documentation.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
Decide whether the event may safely trigger action
The right fallback depends on the consequence of a forged request. A low-impact notification may be useful as a prompt for a constrained workflow. But an unsigned payload should not, by itself, authorize a sensitive operation. For a consequential event, use it as a signal to fetch the current state through a separately authenticated API, then apply your own business rules. If you cannot verify the state or accept the residual risk, do not use the integration for that action.
Know what each safeguard can—and cannot—do
| Control | Useful for | Does not establish by itself |
|---|---|---|
| Verified request signature | Detecting body tampering and providing evidence that the sender had the shared signing secret. | That the event satisfies your business rules or is safe to process more than once. |
| HTTPS with certificate validation | Protecting the transport and helping prevent some in-transit modification. | That a request to your public endpoint was created by the expected provider application. |
| Source-IP allowlist | Filtering traffic from addresses outside a configured provider range. | Message integrity or a stable provider identity if addresses change or infrastructure is shared. |
| Secret URL or token | Restricting access if the credential remains confidential and is correctly checked. | Body integrity unless the credential is cryptographically bound to the body; a leaked credential is no longer secret. |
| Event ID, deduplication, and idempotency | Reducing duplicate processing and some consequences of repeated deliveries. | Authenticity of the first request carrying that ID. |
| Payload and schema validation | Rejecting malformed data or values outside expected rules. | Sender identity. |
This distinction matters: HTTPS, an obscure endpoint URL, IP filtering, validation, and deduplication can reduce exposure or processing errors, but none is equivalent to verifying a signature. GitHub’s webhook best practices and the OWASP draft discuss these controls in their different roles; treat them as defense in depth, not proof of origin.
If you must receive unsigned requests, constrain the endpoint
- Require HTTPS and keep certificate validation enabled.
- If the provider publishes stable source-address ranges, consider an allowlist and keep it maintained. GitHub notes its delivery addresses can change, so allowlisting needs periodic updates; the OWASP draft also cautions that maintaining provider ranges can be complex.
- Accept only the HTTP methods and event types you need. Validate the event type, action, payload shape, and business rules before processing; subscribe only to necessary events.
- Limit payload size and request rate, and expose as little endpoint functionality as possible.
- Deduplicate deliveries and make handlers idempotent so retries do not repeat an operation. These measures address duplicate processing, not whether the original request was genuine.
- Keep credentials out of payload URLs, source code, and logs. Store any secrets securely and rotate them when appropriate.
Use signing correctly when it is available
Follow the provider’s exact scheme and prefer its official library or documentation; signature formats differ. GitHub’s example uses HMAC-SHA256, a sha256= prefix, UTF-8, and constant-time comparison. If the scheme signs the body, verify the exact request bytes before parsing or acting on them. A proxy or load balancer that changes the body or relevant headers can break verification.
Rank #2
- The Shelly Pro 3EM 3CT 63 is a next-gen DIN rail-mountable energy meter for single or three-phase installations, featuring a 63A, 3-phase current transformer for non-contact measurements. It supports 4-quadrant measurement, optical pulse indication of energy usage, and is photovoltaic-ready. *It doesn't have a built-in relay; contactor control requires a Shelly Pro Addon attached to the device.
- Professional Smart Meter - Shelly Pro 3EM-3CT63 is a professional smart meter that reports accumulated energy, voltage, current, active, and apparent power per phase in real time. It stores data for up to 60 days in 1-minute intervals and includes a real-time clock to maintain accurate time if the SNTP server connection is lost.
- Ideal for business energy measurement - In commercial buildings, it helps monitor energy usage across floors or departments allowing accurate cost allocation and identification of energy wastage. In manufacturing plants it tracks energy consumption of heavy machinery, optimizing usage to reduce operational costs. For store owners it monitors energy usage of systems like lighting, HVAC § refrigeration, helping to identify inefficiencies § reduce energy bills while supporting sustainable practices
- Shelly Customer Service - Shelly is one of the fastest-growing Smart Home brands in the world with devices, providing solutions for the automation of private homes, buildings and businesses. We provide our customers with professional support and a 5 years device warranty.
- Shelly Smart Control App will help you control your Shelly devices remotely and will send notifications for all automated events in your home. You can easily configure devices and manage their settings individually, or you can create personalized scenes by combining Shelly devices to trigger certain actions in your home automation.
Reject missing or invalid signatures on an endpoint configured to require them. Do not switch to accepting unsigned requests during an outage unless you have deliberately assessed and approved the change in risk. A delivery ID is not a substitute for a signature: it can help identify a delivery and handle redelivery, but it does not authenticate the request.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Plan for delivery handling and ongoing changes
Keep the endpoint’s response path short. GitHub says a receiver should return a 2XX response within 10 seconds; otherwise GitHub terminates the connection and considers the delivery failed. If processing takes longer, acknowledge promptly after safely recording the delivery, then handle work asynchronously where your design permits.
Recheck the provider’s official documentation periodically, especially if your decision relies on IP ranges or a particular authentication feature. Reassess the integration if the events it can trigger gain authority over more consequential actions.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




