Cookbook / External integrations
Receive a signed webhook.
An important application task with a framework boundary to resolve before a supported recipe can ship.
Framework gapTarget: 0.4.0Not yet recipe-tested
The current boundary
Caramel’s application pipeline parses form input and checks CSRF on write methods before dispatch. A typical external webhook sends a JSON body and cannot supply a browser’s CSRF token.
What a supported path needs
- Access to the unmodified signed body API decision
- Provider signature verification Recipe + tests
- Replay and duplicate-delivery handling Recipe + tests
- A deliberate per-route request policy Framework work
- Invalid signature and retry cases Acceptance tests
Keep this gap visible
Do not disable CSRF across the application or patch a framework class to make a cookbook example appear complete. Publish this recipe when the supported extension point is defined.