Securely receive and handle an inbound webhook from a third party (Stripe, GitHub, Shopify, etc.) — verify the signature, reject replays, acknowledge fast, and process idempotently — so forged or duplicated events can't harm the system. Use when the user says "handle this webhook", "verify a webhook signature", "add a Stripe/GitHub webhook endpoint", "secure my webhook", "my webhook fires twice", or "process incoming events from X".