Webhooks: every event, to your own addresses, signed and retried
A new webhooks service subscribes to the event bus and delivers each event to the repository and workspace webhooks that want it: an HTTPS POST of JSON naming the repository, workspace and actor, signed with HMAC-SHA256 in X-G1t-Signature-256. A receiver that does not answer with a 2xx within ten seconds is tried again after 1m, 5m, 30m, 2h and 5h. Every delivery is kept for a fortnight with its request and response, and can be redelivered. Addresses must be public HTTPS; private and local ones are refused. Each event reaches a webhook once. Members manage a repository's webhooks under its settings, now with General and Webhooks tabs; owners manage the workspace's under Settings. Seven API and MCP tools cover both. The secret sealing that integrations used moves into a shared crate, g1t-secrets. Also: an address no route matches now shows its 404 inside the signed-in sidebar instead of the public frame.
No changes