Is there any way of authenticate the messages sent by JIRA (webhooks)?
Quoting GitHub:
Once your server is configured to receive payloads, it’ll listen for any payload sent to the endpoint you configured.
For security reasons, you probably want to limit requests to those coming from GitHub.
There are a few ways to go about this–for example, you could opt to whitelist requests from GitHub’s IP address–but a far easier method is to set up a secret token and validate the information.
...
When your secret token is set, GitHub uses it to create a hash signature with each payload. You can find details on the implementation in our Ruby implementation.