Cybatar includes a signed webhook ingestion workflow with per-endpoint secrets, optional IP allowlists, payload limits and ingestion-attempt records.
What Cybatar can represent
What is not claimed
Implementation questions
Related Cybatar surfaces
Frequently asked questions
Does Cybatar verify webhook signatures?
Yes. The current receiver verifies timestamped HMAC-signed requests using Cybatar signature headers and the endpoint shared secret.
Can webhook endpoints restrict source IPs?
Yes. The current endpoint model supports an optional list of allowed IP addresses.
What payload limits are enforced?
The current receiver rejects payloads larger than 2 MB and batches containing more than 5,000 events.
Connector availability depends on deployment configuration, credentials, source APIs, data formats and enabled modules. Public connector pages do not claim vendor certification, marketplace approval, complete field coverage, real-time delivery guarantees, universal API support or a successful connection to a third-party service unless that is verified in the specific deployment.