Security and data handling
Webhook payloads can contain sensitive application, customer, payment, or authentication data. Review the dedicated security and data pages before capturing production traffic.
Start with the security overview
The security overview explains account boundaries, signature verification, capture URLs, public share links, replay safety, and customer responsibilities.
Review the data lifecycle
- Data handling
- Data retention
- Data deletion
- Sensitive data
- Subprocessors
Public share links
Sensitive request headers are masked in public debug responses, but payload data remains visible. Review the event, set a short expiry, and revoke the link after use.