To get events for a single referral, register a per-referral webhook with its own token and expiry (
POST /referrals/{id}/webhooks).
Verify signatures
Deliveries follow Standard Webhooks. Each one carrieswebhook-id, webhook-timestamp and webhook-signature headers. Verify them with the secret returned when you registered the endpoint.
webhook-id, so deduplicate on it.

