Message ID (msg_…), the same on every retry of this message. Use it to skip duplicates.
v1,<base64 HMAC-SHA256> of {webhook-id}.{webhook-timestamp}.{raw body}, keyed with the base64-decoded part of your signing secret after whsec_. Several signatures may be space-separated during a secret rotation; accept the message if any one matches.
Message ID; equals the webhook-id header
v1 offer response - wraps domain OfferRead with prefixed IDs.
Final: the message is not retried. This covers 400, 401, 403, 404 and every other 4xx except 408 and 429, which are retried like a 5xx.
Retried. So are 408, 429, a redirect, no response within 15 seconds, and a connection error: 8 attempts in all over about 28 hours, waiting 5 s, 5 min, 30 min, 2 h, 5 h, 10 h, 10 h between them (each ±20%). After the last attempt the message is sent again only if you replay it.