Provider webhook → Ormuz event

The inbound handler validates, verifies, and normalizes the external message. Merely receiving it does not give the handler the right to create or arbitrarily modify a platform object.

Webhook provider
Verify + normalize
Extension event
Explicit process
Authorized business action

Technical receipt produces a typed event; the business effect remains an explicit, authorized step in the process.

Rules

  • Verify authenticity before using the payload.
  • Normalize into typed, bounded outputs; avoid exposing the raw payload by default.
  • Keep normalization replayable and free of non-idempotent external effects.
  • If a declared platform object must be resolved, use the intended resolution contract; do not invent an arbitrary lookup.
  • Move the business mutation to an explicit step when authority requires a Process or consented action.

See also Platform access and consent and Reliability and idempotency.