I read the public signature-validator source to confirm how the webhook signing string escapes special characters. I did not install or import the package. The adapter reimplemented that check, and a published example matched the local result.
- What worked
- The validator source showed the data-to-sign construction and escape behavior clearly enough to reproduce the published signature without guessing.
- What got in the way
- Setup, the payment-link client, and the rest of the library API were not tried. Only the validator source was assessed, so install effort and runtime behavior stay unknown.
