Why this matters
HMAC verification, constant-time comparison and why string equality is a vulnerability.
Recovery pipelines fail quietly: a dropped webhook or a duplicated send does not throw an error, it just costs revenue or trust. The engineering here is about making failure loud and bounded.
The implementation rules
Compute the HMAC over the raw request body, never the parsed JSON. Compare with a timing-safe function; `===` leaks byte position through response time. Reject before any database write, and return 401 without detail.
Each rule is cheap to implement on day one and expensive to retrofit once volume arrives.
How much of your involuntary churn is recoverable?
Compares a 40% single-channel baseline against the 63.8% RRLabs platform average.
- At risk / month
- $5,600
- Extra recovered / month
- $1,333
- Annualised, less $3,000 plan
- $12,994
How RRLabs does it
Signed payload in, HMAC verified, deduplicated on provider event id, written into a row-level-security-scoped table, then routed to the AI copy engine with per-tier timeouts.
Every step is logged with latency, so a regression shows up as a shifted percentile rather than a support ticket.