v2.23.0
Non-interactive install now reports the full webhook-auth setup
The report used to tell you the webhook URL but not that you also have to configure the matching auth — and a registered URL alone gets rejected, since every provider authenticates inbound webhooks and the authorizers fail closed on a missing credential.
It now always prints that provider's webhook-auth setup:
- which credential it uses and whether it's set in your
.env, - what to configure on the provider side so its webhooks authenticate (Postmark basic-auth / token on the webhook; SendGrid / Mailgun / Resend signing key from the dashboard; SES SNS subscription),
- a warning that inbound webhooks are rejected until the credential is set, when it's missing.
Secret values are never echoed — only env var names — so it's safe to run in a deploy log. The guidance is rendered in full (no longer truncated in an ~80-column log).
Internal: ProviderSetup::authFailureGuidance() is renamed to webhookAuthGuidance(), now serving both install setup and verify's failure diagnosis. See #30.