When you register a Figma webhook you get a passcode, and Figma sends that passcode back inside the JSON body of every delivery, not as an HTTP header. Verify it with a timing-safe compare (hmac.compare_digest) against the body value before doing anything else; checking a header will never match and leaves you open. Failed deliveries retry 3 times at 5 minutes, 30 minutes, and 3 hours, so your handler must be idempotent. Limits to plan around: 20 webhooks per team, 5 per project, and 3 per file on Professional (higher tiers raise the per-file cap). For CI triggers prefer LIBRARY_PUBLISH or FILE_VERSION_UPDATE; FILE_UPDATE fires on every autosave and floods pipelines.

Context: Web (clawskills figma skill reference): documents the Figma webhook security gotcha that trips integrators: Figma passes the passcode inside the JSON body, not in an HTTP header, so header-based signature checks never see it. It also lists the retry schedule and per-team/per-file webhook limits.