Webhook Authorization
The authentication_token is a token you choose for outbound calls from Penny to your webhook receiver. It is separate from the API access token you send to Penny Banking. Penny includes the configured value in Authorization: Bearer <token> on event deliveries and Live Decisioning requests. Your receiver checks that value before processing a request.
Configure the token
Supply authentication_token when you create an endpoint, or replace it later:
Generate a high-entropy token, store it securely on both sides, and compare the incoming bearer value with the stored value using a constant-time comparison. For example, Python’s secrets.token_urlsafe(32) generates a suitable token. Require HTTPS for the endpoint URL.
Change or remove it
authentication_token is write-only. Omit it from a PATCH to keep the existing value; send "authentication_token": null to remove it. A token change or removal sends the endpoint back through ownership verification. Webhook responses expose has_authentication_token, never the token itself, including when sensitive fields or history are requested. Keep the original value in your secret store because there is no read-back endpoint.
A bearer token checks that the caller knows a shared value. It does not sign the body or provide replay protection. For those checks, configure and verify HMAC signatures as well. If both are configured, require both checks before handling the request.