To provide additional security a HTTP header X-Hub-Signature is included in each POST payload, which you should use to verify that the payload came from a Facebook server. For full details of this behavior, refer to the Facebook Webhook Framework documentation.
https://developers.facebook.com/docs/workplace/reference/webhooks/

