Private network guide
How to Receive Events Without a Public Webhook Endpoint
A receiver can retrieve pending work through outbound polling instead of accepting inbound requests from a sender.
Reverse the connection direction
Instead of asking a private application to expose an endpoint, let it make an outbound HTTPS request on its own schedule. A relay stores the event in a mailbox and returns it to the authenticated receiver.
Sender --authenticated create--> relay mailbox
Receiver --authenticated poll--> relay mailbox
Receiver --ACK after processing--> relay
Why this fits private systems
Outbound polling can work with NAT, firewalls, shared hosting, local gateways and customer-installed software where inbound routing is difficult or undesirable. The trade-off is polling latency and the need to choose a sensible interval.
Security basics
Authenticate every read and write, bind credentials to an application, protect against replay, use idempotency for uncertain creates, limit payload size and rate-limit the application. Make the receiver's business action safe to repeat.
HeartbeatHook's boundary
The current Tier 1 contract provides HMAC-authenticated signal creation, pending reads and ACK. It does not provide generic webhook delivery, exactly-once execution or large payload transport. See signal relay and webhook alternative.