Skip to content

DL-254

The Linear Agent Session responder is a plain POST /webhooks http.Handler mounted on the compass-server network TLS door (inside buildNetworkServer, beside the Connect mounts, inheriting the G112/RIG-1298 guards; NOT a Connect service, NOT a dedicated ingress), fail-closed on the raw-body HMAC-SHA256 Linear-Signature check (bad/missing signature → 400; a stale-but-validly-signed webhookTimestamp is 200-with-drop, never a retry-burning 400), acking 200 before any work (Linear’s 5s SLA) with all agent work async; the public base URL (webhook host + deep-link base) is a per-deployment config value, never hardcoded

Status: Active (Matt, 2026-08-25)

Record: ../../server/compass-linear-agent-responder/design.md#part-1–the-webhook-receiver-on-the-network-door