How to verify
Your workspace has a global HMAC secret, this secret can be viewed and (re)generated by workspace admins in Settings → Request signing. If you have a HMAC secret set up, when you receive a request from Plain you will see a headerPlain-Request-Signature
with the HMAC signature.
You can verify this signature by hashing the request body with your HMAC secret and comparing it to the signature in the header.
The signature is a HMAC-SHA256 hash of the request body, encoded as a hexadecimal string.