
A valid webhook signature is not authorization
Verifying an HMAC (or other) webhook signature proves the payload came from the vendor. It does not prove which tenant, user, or resource that event is allowed to change in your system.
Verifying an HMAC (or other) webhook signature proves the payload came from the vendor.