Skip to content
Workspace
Contact
Status
Owner
Tags

Each webhook request carries an X-Signature header: an HMAC-SHA256 of the raw body using your signing secret.

  1. Read the raw request body before parsing JSON.
  2. Compute the HMAC with your signing secret.
  3. Compare in constant time and reject on mismatch.
verify.tsts
1import { createHmac, timingSafeEqual } from "node:crypto"
2
3export function verify(rawBody: string, signature: string, secret: string) {
4 const expected = createHmac("sha256", secret).update(rawBody).digest("hex")
5 return timingSafeEqual(Buffer.from(expected), Buffer.from(signature))
6}

Never log the signing secret, and rotate it from Settings if it was ever committed to a repository.


Pages inside

Comments

V