Back to Integrations Guides

Every outgoing webhook arrives with these HTTP headers.

HeaderAlways sent?ValueWhat it’s for
Content-TypeYesapplication/jsonTells you the body is JSON.
SignatureYesHex stringThe HMAC-SHA256 fingerprint of the raw body, made with your secret. Use it to confirm the message is genuine.
X-Webhook-Delivery-IdYesUUIDA per-delivery ID that stays the same across retries. Use it to ignore duplicates.
User-AgentYesAaardvarkWebhooks/1.0Let’s you recognize AAArdvark traffic in your logs and load balancers.
X-Webhook-ReplayOnly on replaystrueMarks the message as part of a historical backfill.


Still stuck?

File a support ticket with our five-star support team to get more help.

File a ticket

  • This field is for validation purposes and should be left unchanged.
  • Please provide any information that will be helpful in helping you get your issue fixed. What have you tried already? What results did you expect? What did you get instead?

Related Guides