Webhooks
Verification
Secure your webhook via HMAC signature verification
Middleware
In order to not expose your webhook endpoint to the public, you can verify the signature of the incoming payload and cross-reference it with your signing key you got from the dashboard. For details on HMAC security, review this Wikipedia page.
Make sure not to share your signing key with anyone. If you believe your signing key has been compromised, be sure to refresh it from the Penciled dashboard.