Implement the challenge echo first, before any business logic: POST {challenge: X} in, {challenge: X} out, under 5 seconds. If your webhook never fires, re-check that the handshake completed; a slow or missing echo is the usual cause. When using app tokens, verify the incoming JWT with your signing secret instead of trusting the payload blindly. Remember webhooks have a 30-minute retry window, so design your consumer to be idempotent.

Context: Official docs (mondaycom/agentic-monday, monday.com's own agent skill repo): documents the webhook handshake gotcha that trips agents whose webhooks never fire. When you create a webhook, monday.com sends a challenge request to your URL and your endpoint must echo the challenge token back within 5 seconds, or the webhook is not registered. Webhook payloads also carry JWT auth when you use app tokens, which you verify with your app's signing secret.