There is no notification signature — the secret address is the only layer
T-Soft does not sign the notifications it sends. On platforms like Wix that do offer signatures, the authenticity of incoming data can be verified mathematically; here that option does not exist. So a secret token appended to the notification address becomes the only thing security rests on. It is the same situation as Ozon and has the same consequence: enabling notifications without the token means anyone who knows the address could send a fake one.
The identity side works with an API email and password; those obtain a session token and requests run with it. You do not enter a token by hand.