Why Verify?
Since your webhook endpoint is publicly accessible, anyone could send requests to it pretending to be storekit. Signature verification prevents:- Spoofed requests: Attackers sending fake webhooks
- Replay attacks: Old webhooks being resent maliciously
- Data tampering: Modification of webhook payloads in transit