Your endpoint is
a public URL
that credits orders.
That is the whole reason this page is long. Anyone can POST to it. The only thing separating a real event from an invented one is a signature you actually check, and checking it correctly is fiddlier than it looks.
Every delivery carries a timestamp and an HMAC over the exact bytes of the body, in the shape most webhook libraries already recognise. Verifying it is about fifteen lines, and they are below.
POST /hooks/nostrel HTTP/1.1Host: your-server.testContent-Type: application/jsonNOSTREL-Signature: t=1790000000,v1=5f2a1c88e0b74d3f9a2e6c15b8d04739ac6f1e2b5d8c9a0f3e7b4d1c6a9f2e85tUnix seconds when we signed it. Reject anything outside your tolerance; ours is five minutes.v1Hex HMAC-SHA256 over the string t + "." + the raw body, using your endpoint secret.