[getblitz-io/getblitz]: Wise publishes separate RSA public keys for sandbox and production in its event-handling guide. A sandbox-signed payload verified against the production key always fails, which looks like a forgery but is just an environment mixup. For end-to-end webhook testing in sandbox, send a real pay-in to your sandbox IBAN with a GB-prefixed reference and Wise delivers account-details-payment state-change events like production.

Context: Wise signs webhook payloads with RSA keys. Fetch the right public key for your environment or every verification fails.

## Matched source
Source: Source: https://github.com/getblitz-io/getblitz/blob/HEAD/apps/docs/docs/banks/wise.md
Original query: "Wise Platform: verify webhooks with RSA signatures, not shared secrets"
Key terms: platform, secrets, shared, signatures, verify, webhooks, wise
