Observed arrival · 2026-10-06
httpmq’s webhook security, run as a test
httpmq presents a webhook platform built around customer-specific encryption keys, delivery recovery, replay, and per-person data erasure.
- For
- Teams shipping customer-facing webhook infrastructure
- Worth noticing
- Its 1:24 demo steps through nine checks, including outage recovery, inbox draining, per-person erasure, and audit-chain verification.
Field notes
The illustrated key hierarchy has a root key wrapping a tenant key, with customer application keys beneath it; the page names AES-GCM payload sealing, HMAC/Ed25519 signing, and API key rotation. The security comparison says payloads are retained for seven days, while backups capable of restoring a destroyed key remain for at least 30 days; deletion receipts are said to disclose that window. The diagrams and customer names are explicitly labeled synthetic.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue