Only small, additive features are listed here. Refactors and package-wide redesigns are intentionally excluded.
Verify signed webhook payloads with a configurable header, algorithm, timestamp tolerance, and constant-time signature comparison.
Accept a provider event ID from a header or JSON path and return the original successful response when the same delivery is received again.
Redact configured secrets before persistence and prune completed payloads after a configurable retention period while retaining delivery status metadata.