REST JSON webhooks for PicoClaw
Most integrations speak HTTPS + JSON. Treat schemas as contracts: version them, validate before calling an LLM, and return fast 200 responses while doing heavy work asynchronously when possible.
1. Schema validation
Reject unknown fields early; cap string lengths to protect token budgets.
2. Idempotency
Use vendor event IDs or content hashes to deduplicate deliveries across retries.
3. Auth
Shared secrets, HMAC signatures, or mTLS—pick per vendor. See API and Security.