For Merge sync webhooks: (1) always return 200 fast, under 5 seconds. A 4xx from your endpoint is treated as permanent failure and the event is dropped with no retry, so never do real work inside the webhook handler; enqueue it and return. (2) Do not rely on webhooks alone. Run a polling backstop in production: periodic `GET /sync-status` checks or a `modified_after` sweep, because a deploy window or a 400 from a framework that cannot parse the payload loses the event outright. (3) If polling shows `sync_status` stuck on SYNCING, that is often just the initial sync taking 15 minutes to several hours on large accounts; confirm `initial_sync_complete` gets set when status reaches DONE. (4) If HMAC validation fails on every event, check two things: the webhook secret matches, and you computed the HMAC against the raw body before JSON parsing (Express `json()` middleware eating the raw body is the classic cause).