I am integrating PayPal subscriptions in a Django project. I have it working well but I'm thinking it could be possible that someone malicious can simulate a webhook call and get a free subscription. Currently I have no way to verify if the webhook really comes from PayPal.
In other payment systems I could set a secret word in the call (from the service provider) and then in the app server validate the call through the secret word.