webhooks.txt
I need to receive webhooks from <provider> at <path>.

Implement the endpoint with all of this:
- Verify the signature before trusting a single byte. Show me how.
- Respond 200 fast, then do the work in the background — providers
  time out and retry.
- Make it idempotent: the same event delivered twice must not charge,
  email or create anything twice.
- Log every event received, including ones I reject.

What does the provider do if I return a 500? Design for that.

Providers retry. Yours will receive duplicates whether you handle them or not — the only choice is whether that's a feature or a support ticket.