Webhook setup

Configure outbound webhooks in Avanora Connect or module-specific settings. Each endpoint receives a signing secret used to compute an HMAC signature header so consumers can reject forged traffic.

Verification checklist

  • Reject payloads when the signature header is missing or does not match the raw request body.
  • Treat retries as idempotent: use delivery ids recorded in meta to deduplicate.
  • Rotate secrets from the control or tenant UI and roll credentials before revoking old secrets in your integration.

Inbound provider webhooks

Billing and infrastructure adapters expose narrowly scoped routes that validate provider-specific headers before updating Control state machines. Keep these handlers free of tenant business logic to simplify auditing.