The webhook documentation and API documentation do not mention how to authenticate a webhook sent to the configured URL. Is there a supported way to do this?
Typically I'd expect a signature to verify or a header with an API key but I don't see either in the requests.
I could hard code an API key into a query param on the configured URL but that seems less than ideal.
Any help would be much appreciated.