Our security team has a preference for having webhook payloads sent authenticated with OAuth Client Credentials, rather than being signed by an HMAC signature.
Your idea is now live and open for voting.