Verified BursaPay workflow: Apply secure engineering practices to webhook receivers.
1. Overview & Purpose
Webhook endpoints should use HTTPS, validate signatures, protect secrets and minimize sensitive logging.
2. Requirements & Setup
A publicly reachable HTTPS endpoint, secure secret storage and structured request logging are required for production readiness.
3. Step-by-Step Workflow
- Terminate TLS correctly.
- Verify webhook signatures.
- Store secrets outside source control.
- Log references and status without storing secrets or unnecessary payment credentials.
4. Rules & Troubleshooting
A webhook endpoint is an internet-facing financial integration surface and should be treated as untrusted input until authenticated.
5. Verification & Next Steps
Run security tests for invalid signature, replay/duplicate, malformed JSON and oversized payload cases.