IDCanopy Developers
Guides

Webhooks

Registration, payloads, signatures, and retries, per service

Webhook mechanics differ per service; each has its own signing scheme and retry policy.

ServiceHeaderAlgorithmRetries
Umbrella SDK (hosted journeys)SignatureHMAC-SHA256 over the raw bodyUp to 6 attempts over ~24h, increasing backoff
Aletheia (outbound result)X-Forensic-SignatureHMAC-SHA256 over the raw body, lowercase hex3 attempts, exponential backoff
Aletheia (inbound URL-fetch)X-Inbound-SignatureHMAC-SHA256 over the raw body, lowercase hexn/a, you send this one

Per-service detail: Umbrella SDK webhooks, Aletheia webhooks.