Ticket OD-202607021939
Redirect Smoke
Age 02/07/2026 · Suggested action: Ask the customer to verify the webhook signing secret in their receiver matches the currently configured secret for this endpoint, confirm they are using the correct signing algorithm/verification method, and avoid resending raw secrets over email. Explain that replaying failed webhook deliveries may create duplicates unless their receiver is idempotent; recommend idempotency checks before replay. Escalate to engineering only if they confirm the secret and verification logic are correct but signatures still fail.
Customer: Nordic Retail Ops From: ops@nordic-retail.example Subject: Webhook deliveries failing after secret rotation Hi OpsDesk, We rotated our webhook signing secret this morning, and since then all invoice.created and payment.succeeded webhook deliveries are failing signature validation on our side. We can see the events are still reaching our endpoint, but our receiver rejects them with "invalid signature". We do not want to send the raw secret over email. Can you confirm what you need from us to fix this safely, and whether replaying the failed events could create duplicates? This is blocking our finance sync for today's orders. Best, Maja ```
Raw intake to structured package
Customer: Nordic Retail Ops From: ops@nordic-retail.example Subject: Webhook deliveries failing after secret rotation Hi OpsDesk, We rotated our webhook signing secret this morning, and since then all invoice.created and payment.succeeded webhook deliveries are failing signature validation on our side. We can see the events are still reaching our endpoint, but our receiver rejects them with "invalid signature". We do not want to send the raw secret over email. Can you confirm what you need from us to fix this safely, and whether replaying the failed events could create duplicates? This is blocking our finance sync for today's orders. Best, Maja ```
Ask the customer to verify the webhook signing secret in their receiver matches the currently configured secret for this endpoint, confirm they are using the correct signing algorithm/verification method, and avoid resending raw secrets over email. Explain that replaying failed webhook deliveries may create duplicates unless their receiver is idempotent; recommend idempotency checks before replay. Escalate to engineering only if they confirm the secret and verification logic are correct but signatures still fail.
Outcome
No draft / escalation
A customer-facing draft would create risk. Route to the required workflow first.
No customer draft generated
This is an intentional safety outcome, not a generation failure.
Ask the customer to verify the webhook signing secret in their receiver matches the currently configured secret for this endpoint, confirm they are using the correct signing algorithm/verification method, and avoid resending raw secrets over email. Explain that replaying failed webhook deliveries may create duplicates unless their receiver is idempotent; recommend idempotency checks before replay. Escalate to engineering only if they confirm the secret and verification logic are correct but signatures still fail.
Ask the customer to verify the webhook signing secret in their receiver matches the currently configured secret for this endpoint, confirm they are using the correct signing algorithm/verification method, and avoid resending raw secrets over email. Explain that replaying failed webhook deliveries may create duplicates unless their receiver is idempotent; recommend idempotency checks before replay. Escalate to engineering only if they confirm the secret and verification logic are correct but signatures still fail.
Review replay
Every reviewer action is persisted for audit and interview walkthroughs.
- CREATE TICKET
Manual ticket created and queued for triage.
Actor: Jiajia · Area: ticket_intake