Are outgoing webhook event payloads signed with a shared secret, and if so, what hashing algorithm is used to verify them?
No page on the site addresses this.
Publish developer documentation or a security FAQ that explains whether outgoing webhooks are signed with a shared secret and documents the hashing algorithm (e.g., HMAC-SHA256) buyers should use to verify payloads.
Where we looked: status.vimeo.com
confidence high · grounding world-knowledge · weight 0.00 · Absent