caramel
Skip to content
Browse documentation
Cookbook / External integrations

Receive a signed webhook.

An important application task with a framework boundary to resolve before a supported recipe can ship.

Framework gapTarget: 0.4.0Not yet recipe-tested

The current boundary

Caramel’s application pipeline parses form input and checks CSRF on write methods before dispatch. A typical external webhook sends a JSON body and cannot supply a browser’s CSRF token.

What a supported path needs

  • Access to the unmodified signed body API decision
  • Provider signature verification Recipe + tests
  • Replay and duplicate-delivery handling Recipe + tests
  • A deliberate per-route request policy Framework work
  • Invalid signature and retry cases Acceptance tests
Keep this gap visible

Do not disable CSRF across the application or patch a framework class to make a cookbook example appear complete. Publish this recipe when the supported extension point is defined.