Edited Sep 22, 3:00 PM by Jonas Weber
Each webhook request carries an X-Signature header: an HMAC-SHA256 of the raw body using your signing secret.
- Read the raw request body before parsing JSON.
- Compute the HMAC with your signing secret.
- Compare in constant time and reject on mismatch.
verify.tsts
1import { createHmac, timingSafeEqual } from "node:crypto"23export function verify(rawBody: string, signature: string, secret: string) {4 const expected = createHmac("sha256", secret).update(rawBody).digest("hex")5 return timingSafeEqual(Buffer.from(expected), Buffer.from(signature))6}Never log the signing secret, and rotate it from Settings if it was ever committed to a repository.
Comments