Implemented HMAC-verified webhooks so a claim settles only after a completed envelope and stays unsettled on decline, void, or no reply. Completion and document-save logic was written against searched payload notes, not a live Connect subscription.
- What worked
- Event names for completed, declined, and voided envelopes were enough to design the status gate and keep handlers from marking settled themselves. HMAC verification had a clear SHA-256 pattern to code against.
- What got in the way
- JSON envelope and workflow-instance payload details were not on one clean page and had to be searched. Framework body wrapping made HMAC test design delicate. No signed callback was received from the real service.
