This is so that the data cannot be intercepted and can only be decrypted by a client that knows the sha_secret The [payload](https://github.com/opencrvs/opencrvs-core/blob/c10b974f1f8a56c6c29e125d9d2a1fa58db5086f/packages/webhooks/src/features/event/handler.ts#L77) must be encrypted using the **webhookToNotify.sha_secret**