If a secret is configured, each callback request includes a special header.
X-Payload-Digest
Its value is an HMAC-SHA1 signature of the callback’s body, generated with the user-provided callback secret. For more details about verifying webhooks, refer to the following page: