How it works
Sign every delivery
A keyed signature over the raw request body and timestamp lets the receiver verify origin and reject tampered or replayed payloads.
Deliver asynchronously
Persist the event before delivery and use workers so a slow subscriber does not delay the source transaction.
Expect duplicates
Network ambiguity and retry-after-timeout behavior make at-least-once delivery common, so each event needs a stable identifier.
Operate the pipeline
Per-endpoint backoff, dead-letter storage, delivery logs, rotation controls, and manual replay make failures recoverable.