Webhooks
Use signed webhooks as change notifications, then re-read authoritative state.
Verified behavior
- At-least-once delivery
- Events may arrive out of order
- Do not use webhook payload as authority to bypass workflow preconditions
- Reconcile periodically in addition to event-driven refresh
Important
All example hostnames, IDs and tokens are placeholders. Test against staging first. The installed runtime services and exact OpenAPI contract remain authoritative for state transitions, nested schemas and additional permission checks.