ORD-015

A requirement the spck.dev suite checks on UCP servers. The quoted text is the normative requirement; the citation links to the exact line of the pinned spec source it was taken from.

Businesses MUST sign all webhook payloads using a key from their signing_keys array (published in /.well-known/ucp), and the signature MUST be included in the Request-Signature header as a detached JWT (RFC 7797)
Keyword
MUST
Area
Order
Versions
2026-01-11 2026-01-23
Testability
needs a receiver the suite controls, so it runs in the CLI/full suite
Spec source
ucp:docs/specification/order.md#L335 2026-01-11
ucp:docs/specification/order.md#L335 2026-01-23

How this is graded

A deviation on a MUST fails the run and shows the requirement next to the actual response. Checks the suite cannot validate soundly are reported inconclusive or not-tested — never a silent pass. The full verdict semantics are on the grading rubric.

Run it against your store

The hosted check covers the read-only surface; the CLI and GitHub Action run the full suite, including this check when your store declares the capability it belongs to.