What is Webhook Timestamp Tolerance?
The maximum acceptable age of a signed webhook before rejection, typically measured in minutes. Tolerance windows block replay attacks while forgiving normal delivery delays and clock skew.
Related terms
Webhook Verification
Cryptographically confirming payment callbacks actually came from the provider before fulfilling orders. Unverified webhooks let anyone grant themselves premium.
Rate Limiting & HTTP 429
Server caps on request volume per client or key, answered with status 429 plus a Retry-After hint when exceeded. Limits protect login, signup, and AI endpoints from abuse and runaway costs.
Open Redirect
A redirect endpoint that forwards users to any attacker-supplied URL, weaponized in phishing. Allowlists of destinations or signed redirect parameters keep navigation features from becoming launchpads.
Cross-Site Request Forgery (CSRF)
An attack that tricks a logged-in browser into submitting unwanted state-changing requests to a trusted site. SameSite cookies, anti-CSRF tokens, and origin checks break the forgery chain.
SQL Injection
An attack that smuggles database commands through unsanitized input into application queries. Parameterized statements and least-privilege database roles keep hostile input as data, never executable code.
CSP Directives
The individual rules inside a Content Security Policy, such as script-src, object-src, and frame-ancestors. Each directive narrows one resource class, so auditing means reviewing directives one by one.