Security checklist
Check each item before going live.
Endpoint
- HTTPS only, with an unexpired certificate from a public CA
- Verify
webhook-signatureagainst the raw body with a constant-time comparison - Reject requests whose
webhook-timestampis more than 5 minutes from now - Deduplicate by
webhook-idwith a unique index - Reply
401on signature failure without error details - Reply
2xxfirst and process asynchronously to avoid timeouts and redeliveries - Limit request size (256 KB recommended)
Keys
- Keep the API key in a secret store; never in code, version control or logs
- Only services that need the key can read it
- Rotate immediately in the App or portal if it may be exposed; the old key expires after 24 hours
- Rotate regularly (yearly recommended)
Data
- Treat event content as untrusted input: validate length and format and use parameterized queries
- Don’t use event content for clinical decisions; the physical label is authoritative
- Don’t store
endpoint.testevents as production data
Source verification
The signature proves the request came from us. Cloudflare egress IPs are shared ranges, so IP allowlists are not recommended as the only control. If your policy requires network-level verification, contact us about mTLS client certificates or a fixed egress IP.
Our side
- We deliver only to public internet addresses; URLs resolving to private, reserved or cloud metadata addresses are rejected
- Redirects are not followed and only the first 4 KB of a response is read
- Scan content is deleted on delivery; keys are stored encrypted with AES-256-GCM
- The App proves its identity with Apple App Attest and App Store–signed subscription transactions