The standard security mechanism in place in my organization is to use a client certificate to validate the authenticity of any request originating from an internet facing source. Currently, webhooks only support the use of a secret key. Please add the ability to upload and register a client certificate which could then be validated.