Manage the tenant delivery webhook used to receive terminal SMS delivery status updates.
Copy this secret now. It will not be shown again.
{{ $revealedSecret }}
Store the secret in an approved secret manager. Do not place it in URLs, logs, source control, or browser storage.
The gateway sends a signed webhook when a correlated delivery receipt reaches
delivered, failed, expired, or
rejected. Each event has at most one delivery attempt; automatic
retries are not implemented.
No webhook is configured for this tenant.
@if ($operations->canManageWebhook) @endif @else @if ($operations->canManageWebhook) @endif @endifThe stored secret is encrypted and cannot be redisplayed. Rotation reveals the replacement once.
@if ($operations->canManageWebhook) @if ($operations->webhook->signingEnabled) @endif @endif
Read the raw request body. Compute HMAC-SHA256 over
X-Webhook-Timestamp + "." + raw_body, prefix the hexadecimal
digest with v1=, and compare it with
X-Webhook-Signature using a constant-time comparison.
Reject timestamps outside the approved five-minute window to limit replay.
$expected = 'v1=' . hash_hmac(
'sha256',
$timestamp . '.' . $rawBody,
$webhookSecret,
);
if (! hash_equals($expected, $signature)) {
http_response_code(401);
exit;
}
The current webhook domain does not implement test-event delivery.