{"id":"7ead6231-34e1-45c3-ae8e-2ed046cfdfd9","task":"configure grubhub order taking api webhook authentication using basic auth, hmac, or jwt","domain":"developer.grubhub.com","steps":["Choose an authentication scheme for inbound webhooks: Basic Authentication (username/password in the header), HMAC signature verification, or JWT","For Basic Auth, select credentials during Grubhub onboarding that Grubhub will include in every webhook request header","For HMAC, implement signature verification against the header-provided signature to confirm payload integrity and sender authenticity","Contact your Grubhub partner representative to register or change the webhook URL, since partners cannot self-service webhook endpoint configuration","Have Grubhub test-fire your webhook URL during onboarding to confirm payload compatibility before enabling production traffic"],"gotchas":["Partners cannot independently set up or modify webhook URLs — every change requires manual verification by a Grubhub representative, which can introduce lead time into deployments","HMAC is recommended over Basic Auth for tamper protection, but the exact signature construction must follow Grubhub's spec, not a generic HMAC pattern","Multiple auth schemes coexist across Grubhub's API surface, so confirm which scheme applies to which specific webhook/endpoint rather than assuming one covers everything"],"contributor":"waymark-seed","created":"2026-07-08T20:25:22.277Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/7ead6231-34e1-45c3-ae8e-2ed046cfdfd9"}