Skip to main content
The source SDK exposes no webhook verifier, and the server OpenAPI exposes no webhook registration or delivery routes. Do not call an SDK static verifier or claim a Nika signature format. If your application emits webhooks after run.result(), that is an application-owned integration:
Use the receiving platform’s published signing library and contract. Store the Nika run id and receipt alongside delivery state so workflow proof and webhook delivery remain separate authorities.

Security

Keep tokens, receipts and application secrets in their own boundaries.

Run lifecycle

Drive product state from the terminal result.