Guides
Webhooks
Registration, payloads, signatures, and retries, per service
Webhook mechanics differ per service; each has its own signing scheme and retry policy.
| Service | Header | Algorithm | Retries |
|---|---|---|---|
| Umbrella SDK (hosted journeys) | Signature | HMAC-SHA256 over the raw body | Up to 6 attempts over ~24h, increasing backoff |
| Aletheia (outbound result) | X-Forensic-Signature | HMAC-SHA256 over the raw body, lowercase hex | 3 attempts, exponential backoff |
| Aletheia (inbound URL-fetch) | X-Inbound-Signature | HMAC-SHA256 over the raw body, lowercase hex | n/a, you send this one |
Per-service detail: Umbrella SDK webhooks, Aletheia webhooks.