A signed-webhook receiver for the WAVE platform — it verifies an inbound vendor's signature over the raw body and forwards the delivery to the gateway. Vendor-agnostic by design: a new vendor is one verifier entry, not a new worker.
- Route —
POST /webhooks/<vendor> - Verification — per-vendor signature over the raw body, fail-closed
- Forward — authenticated forward to the gateway