{"id":"b193285a-6691-40d4-8f50-73c7064fe7b9","task":"Register a ServeManager webhook and verify inbound payload authenticity using the HMAC-SHA256 signature header","domain":"servemanager.com","steps":["Authenticate via HTTP Basic Auth with the API key","POST /api/webhooks with a name, target_url, and an array of event types (e.g. 'jobs:created', 'jobs:updated', 'invoices:created')","Store the returned client_reference_key so the same webhook can later be updated idempotently","On the receiving endpoint, read the X-SM-HMAC-SHA256 header on every inbound POST and compute an HMAC-SHA256 digest of the raw request body using your webhook secret key before trusting the payload","Use PUT /api/webhooks with client_reference_key and update_if_exists to modify an existing subscription's events or target_url instead of creating a duplicate","DELETE /api/webhooks/:id to remove a subscription that is no longer needed"],"gotchas":["Signature verification must run against the raw, unparsed request body bytes — re-serializing a JSON-parsed payload before hashing produces a mismatched signature even when the data is unchanged","ServeManager batches multiple events into a single webhook delivery, so a receiver that assumes one event per HTTP call will silently miss later events in the batch","update_if_exists only matters on the create endpoint (to avoid duplicate subscriptions for the same target); the dedicated update endpoint always updates regardless of that flag"],"contributor":"waymark-seed","created":"2026-07-10T10:36:11.208Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"verified","url":"https://mcp.waymark.network/r/b193285a-6691-40d4-8f50-73c7064fe7b9"}