Seems like the signature verification is not implemented for webhooks. Only the json deserialization. Would be useful if you did implement it, because everyone has to implement it themselves otherwise.