LinkedDataNotificationsSubscription2021 uses webid in the subscription response explaining:
All LDN notifications will be sent to the defined inbox using the agent identity specified by this WebID. A resource owner should ensure that the agent identified in this property is permitted to send authenticated HTTP requests to the defined inbox.
I think WebHookSubscription2021 and all target flow types, in general, could use this as a common approach.
@jaxoncreed what do you think about using this approach instead of defining custom AuthN?
https://github.com/solid/notifications/blob/main/webhook-subscription.md#10-webhook-request-with-token-signed-by-the-pod-key