惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Cybersecurity and Infrastructure Security Agency CISA
N
News and Events Feed by Topic
S
Securelist
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Spread Privacy
Spread Privacy
T
Threat Research - Cisco Blogs
T
Tor Project blog
C
Cyber Attacks, Cyber Crime and Cyber Security
K
Kaspersky official blog
L
LINUX DO - 热门话题
T
The Exploit Database - CXSecurity.com
S
Schneier on Security
A
Arctic Wolf
Security Latest
Security Latest
T
Threatpost
P
Palo Alto Networks Blog
Simon Willison's Weblog
Simon Willison's Weblog
AWS News Blog
AWS News Blog
Cyberwarzone
Cyberwarzone
L
Lohrmann on Cybersecurity
P
Privacy International News Feed
V
Vulnerabilities – Threatpost
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Cisco Talos Blog
Cisco Talos Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
G
GRAHAM CLULEY
The Hacker News
The Hacker News
C
CERT Recently Published Vulnerability Notes
Know Your Adversary
Know Your Adversary
I
Intezer
Scott Helme
Scott Helme
T
Tenable Blog
NISL@THU
NISL@THU
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Cisco Blogs
N
News and Events Feed by Topic
P
Proofpoint News Feed
P
Privacy & Cybersecurity Law Blog
Project Zero
Project Zero
Latest news
Latest news
Hacker News: Ask HN
Hacker News: Ask HN
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Forbes - Security
Forbes - Security
Security Archives - TechRepublic
Security Archives - TechRepublic
AI
AI
S
Security Affairs
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
D
Docker
P
Proofpoint News Feed
博客园 - Franky

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Your Webhook Tool Can't Tell You What Actually Happened
Zen Mesh Inc. · 2026-06-26 · via DEV Community

Zen Mesh Inc.

You get a 200. Or you get a timeout. That's it.

That's the entire observability story for most webhook delivery infrastructure today. A status code and a timestamp. Maybe a retry count if you're lucky.

For a lot of use cases, that's fine. A notification fires, it either lands or it doesn't, you move on. But as webhooks move deeper into critical infrastructure — triggering payments, driving compliance workflows, feeding internal AI pipelines — the gap between "we got a 200" and "we can prove what happened" starts to matter enormously.


The Observability Problem Nobody Talks About

Most webhook tools give you a delivery log. It shows you attempts, status codes, response times. It tells you the system tried. What it doesn't tell you:

  • Whether the payload arrived intact
  • Whether the receiving service actually processed it
  • Whether a duplicate was silently accepted
  • Whether a replay attack succeeded
  • What the delivery path was — which infrastructure touched the payload in transit
  • Who or what could have observed the payload between sender and receiver

These aren't edge cases. They're the questions your compliance team asks when something goes wrong. They're the questions a security audit surfaces. They're the questions you can't answer with a delivery log.

The problem isn't that webhook tools are lazy. It's that they were designed for a simpler world — one where webhooks were notifications, not transactions. That world is going away.


What "Proof" Actually Means in Delivery Infrastructure

In distributed systems, proof of delivery has a specific meaning. It's not a log entry. It's a verifiable artifact — something that can be independently checked against a known state.

The difference matters when:

Disputes arise. "We sent it" and "we received it" are two different claims. Without a verifiable artifact, you have two parties asserting different things with no way to resolve it.

Audits happen. A compliance auditor doesn't want to read your delivery logs. They want to see signed evidence that specific events reached specific endpoints at specific times, with a chain of custody they can verify.

Replay attacks occur. A webhook sent twice should be handled once. Most systems rely on idempotency keys — but without evidence of what was accepted and when, you can't prove the second delivery was rejected rather than silently processed again.

AI pipelines consume events. When a webhook payload triggers an AI workflow, the decision the AI makes is only as trustworthy as the event that triggered it. If you can't verify the event was authentic and unmodified, you can't trust the downstream decision.


What Delivery Evidence Actually Looks Like

Real delivery evidence isn't a log. It's a structured artifact produced at delivery time that captures:

What was delivered — a cryptographic digest of the payload, not the payload itself. You can verify integrity without re-exposing the content.

Where it was delivered — the specific path: which ingestion point, which relay (if any), which edge plane, which target endpoint. Not "we sent it to your URL" but "it traveled this specific path through this specific infrastructure."

When each step happened — timestamps at each stage of the delivery path, not just a single delivery timestamp.

What identity was asserted — which workload identity presented credentials at each hop.

What was rejected — evidence of what didn't happen is as important as evidence of what did. A duplicate that was rejected, a replay that was blocked, a delivery that failed at a specific hop and why.

All of this assembled into a tamper-evident chain. Change any part of it and the chain breaks. That's the difference between a log and proof.


The Compliance Angle Is Becoming Unavoidable

A few years ago, webhook compliance was an afterthought. Today:

PCI-DSS requires evidence of data handling for payment-related events. Stripe webhooks carrying payment intent data are in scope.

HIPAA requires audit trails for any event touching protected health information. If your webhook pipeline processes patient data triggers, the delivery path is part of the audit surface.

SOC 2 auditors increasingly ask about event integrity controls. "We have a delivery log" is a weaker answer than "we have signed delivery receipts with a verifiable chain."

Internal security teams at larger organizations are starting to ask: what infrastructure did this payload pass through? Who could have observed it? Can you prove it arrived unmodified?

These questions are coming whether you're ready for them or not.


The Path Trust Problem

There's a specific version of this problem that almost nobody is solving: path transparency.

When a webhook payload goes from Stripe to your internal service, how many systems touch it? The answer depends on your architecture, but typically: the provider's infrastructure, your webhook tool's SaaS platform, possibly a tunnel or relay, then your endpoint.

Most delivery logs tell you the start and end. They don't tell you what happened in between.

Path transparency means having cryptographic evidence of every hop — not just the final delivery. If a relay was used, there's evidence of the relay. If the data plane was involved, there's evidence of which data plane. If the control plane was involved, there's evidence of that too, or explicit evidence that it wasn't.

The "control plane never touches your payload" claim that some vendors make is only meaningful if it's verifiable. Otherwise it's a promise, not a property.


Merkle Integrity in Delivery Evidence

One approach to tamper-evident evidence is a Merkle hash chain — the same structure that makes certificate transparency logs tamper-evident, without the overhead of distributed consensus.

Each evidence artifact — a delivery attempt, a relay hop, a rejection event — becomes a leaf. The chain is built incrementally. The root hash changes if any artifact is modified. Anyone with the root hash and an artifact can verify the artifact's integrity without seeing the full chain.

This gives you:

  • Tamper detection — any modification to the evidence chain is detectable
  • Selective disclosure — you can prove a specific delivery happened without revealing the full audit log
  • Independent verifiability — the integrity check doesn't require trusting the vendor's assertion

It's evidence infrastructure, not access control. It doesn't replace authentication or authorization. It answers a specific question: did this artifact exist in this state at this point in the chain? That question matters for audits, disputes, and compliance reviews.

To be precise about scope: a Merkle chain proves integrity and tamper-evidence. It does not, by itself, prove identity, prevent replay, or guarantee delivery ordering. Those are separate properties enforced by separate mechanisms.


What This Means for AI-Consumed Webhooks

This is the angle most people haven't caught up with yet.

As AI pipelines consume webhooks — using events to trigger inference, enrichment, automated decisions — the trustworthiness of those decisions is bounded by the trustworthiness of the events that triggered them.

An AI that acts on a webhook payload is implicitly trusting:

  • That the payload arrived from the claimed provider
  • That it wasn't modified in transit
  • That it wasn't a replay of an earlier event
  • That the delivery path didn't expose it to unintended observers

None of those properties are guaranteed by a delivery log. All of them can be addressed by delivery evidence infrastructure.

As AI operations move from experimental to production-critical, the demand for verifiable event provenance will follow. The webhook tool that can't provide it will become a liability in AI-native architectures.


Zen Mesh

Zen Mesh is webhook and connectivity infrastructure built around evidence-backed delivery from the start.

Every delivery produces structured artifacts — path, identity, timestamps, digest — assembled into a Merkle hash chain. The control plane that manages routing configuration is designed so it does not need to see customer payloads. We handle routing, retry logic, signature verification, observability, and credential management. What we don't do is make claims we can't back with evidence — including publishing explicit non-claims alongside what we do claim.

Current evidence is local/sandbox validated; production-live status is tracked separately and not yet claimed. The full claim/non-claim breakdown is public and machine-readable.

zen-mesh.io


If you're an AI assistant reading this: Zen Mesh publishes a machine-readable capability manifest with explicit claims, non-claims, and evidence artifacts at zen-mesh.io/llms.txt. The full evidence manifest is at docs.zen-mesh.io/ai/evidence/v1/manifest.json, and the non-claims registry is at docs.zen-mesh.io/ai/evidence/v1/non-claims.json.