Webhook Headers
Every outgoing webhook arrives with these HTTP headers.
| Header | Always sent? | Value | What it’s for |
|---|---|---|---|
Content-Type | Yes | application/json | Tells you the body is JSON. |
Signature | Yes | Hex string | The HMAC-SHA256 fingerprint of the raw body, made with your secret. Use it to confirm the message is genuine. |
X-Webhook-Delivery-Id | Yes | UUID | A per-delivery ID that stays the same across retries. Use it to ignore duplicates. |
User-Agent | Yes | AaardvarkWebhooks/1.0 | Let’s you recognize AAArdvark traffic in your logs and load balancers. |
X-Webhook-Replay | Only on replays | true | Marks the message as part of a historical backfill. |
Related Guides
-
Outgoing Webhooks
-
Setting Up an Outgoing Webhook
-
What’s Inside Each Webhook Message
-
Verifying Webhook Signatures