How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Forge Event Hooks should be signed

calendar_today September 18, 2026 person @AaronMorris1 Aaron Morris domain trello

I generally agree with this, but I’d like to pose two questions: scottjackson: If someone was able to forge a FIT somehow and hit an application endpoint with a malicious body, there’s no way on the application side to reject the forged body. FITs are cryptographically signed by Atlassian. So isn’t a stolen or leaked FIT a more likely threat than a forged FIT?

open_in_new Read original post