Deserialize GoCardless webhooks into a root object that has an events list, not into a single event. The body shape is an object with an events array, each entry carrying id, resource_type, action, links, and details. In .NET that means a Root class with a List of the SDK's event resource, then read each event's action to route it. If webhook parsing throws, check the wrapper shape first before suspecting the signature or the stream reading.

Context: Stack Overflow #45413721 (top answer, 4 votes): A .NET developer read the GoCardless webhook request stream into a string and tried to deserialize it straight into an event object, which failed. The payload is not a bare event; it is a wrapper object holding an events array, so direct deserialization into the event type cannot work.