> ## Documentation Index
> Fetch the complete documentation index at: https://docs.triplesession.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Private recordings and signed webhooks

> Review recordings stored behind authentication, and sign webhook notifications so the secret never travels with the request.

<div style={{display: 'inline-flex', alignItems: 'center', gap: '0.5rem', fontSize: '0.875rem', color: '#6b7280', lineHeight: 1, marginBottom: '1rem'}}><span style={{lineHeight: 1}}>September 29, 2026</span><Badge>New</Badge></div>

Two optional additions to **Webhook Received** automations with a **Review Meeting** action. The default setup, with the API key header and a public or pre-signed recording link, doesn't change.

## Review recordings that aren't public

Your recordings no longer need a public or pre-signed link. In the **Review Meeting** action, open **Recording source authentication** and enter a Basic, Bearer or API key credential, plus the one host it may be sent to. Triple Session downloads each recording you notify it about with that credential.

The credential is encrypted when you save it, is never shown again, and is only ever sent over HTTPS to the pinned host. Replace it at any time without downtime.

## Signed webhook requests

Notifications can now be signed instead of carrying the API key. The secret never travels with the request, and a captured request stops working after 5 minutes. Select **Signed requests only** on the trigger to reject anything unsigned.

Existing integrations keep working unchanged: the API key header, JSON and form-encoded bodies are all still accepted.

See [Signed requests](/automations/review-meeting-webhook#signed-requests) and [Recordings behind authentication](/automations/review-meeting-webhook#recordings-behind-authentication) for setup, the Recording source contract, security details and Node.js, PowerShell and curl samples.
