# Developer Center webhook operations

The Developer Center Webhook tab is available at the tenant-scoped named route
`developer.webhook.index`. An application is selected with its public ID in the
`application` query parameter. The selector is restricted to applications in the
active tenant workspace.

Webhook delivery configuration remains tenant-wide. Selecting an application
provides application-scoped readiness and delivery evidence while the existing
webhook configuration is shared by the tenant. The UI delegates create, replace,
enable, disable, secret rotation, and secret revocation to
`DeveloperOperationsCommandService`; it does not write webhook models directly.

Endpoint validation remains authoritative in `WebhookEndpointValidator`. It
requires a public HTTPS destination and blocks unsafe or unresolved targets. The
UI does not make test HTTP requests.

Creating or rotating a signing secret returns it once in a non-cacheable response.
Subsequent pages show only the configured/revoked state. Plaintext secrets are not
written to audit metadata or logs. Disabling preserves the configuration and
delivery history; revoking the secret also disables delivery.

The current canonical events are terminal SMS delivery states: `delivered`,
`failed`, `expired`, and `rejected`. Receivers verify `X-Webhook-Signature` as an
HMAC-SHA256 signature over `X-Webhook-Timestamp + "." + raw_body` and enforce the
approved five-minute timestamp window. Automatic retries and UI test deliveries
are not currently implemented.

All UI links, forms, redirects, and documentation resources use named routes or
the existing resource service and preserve both root and subdirectory deployments.
