Every Message webhook carries an HMAC-SHA256 signature in the X-Message-Signature header. The shared secret lives in your workspace at Settings > Webhooks > Signing secret.
Verify in Node
Compute hmac('sha256', secret).update(rawBody).digest('hex') and compare to the header in constant time (crypto.timingSafeEqual). See /developers/webhooks/signature-verification for examples in Python, PHP, Ruby.
Rotate the secret
Settings > Webhooks > Rotate. Old secret stays valid for 24 hours. Update your verifier within 24 hours.