Review or design inbound and outbound webhook security, event authenticity, replay prevention, idempotency, queue handoff, retries, and webhook secret handling. Use whenever external providers send events to the application or the application delivers signed callbacks to other systems.