Documentation · Webhooks

Webhooks · Security

Signature verification, replay windows and endpoint hardening.

Needs Verification
Purpose
Ensure only genuine, fresh events mutate your data.
Prerequisites
  • Signing secret
Architecture
Signature covers timestamp and raw body; verification must use the raw bytes.

Configuration

Replay window300 seconds

Implementation steps

  1. 01Capture the raw body before JSON parsing
  2. 02Compute HMAC and compare in constant time
  3. 03Reject stale timestamps
  4. 04Rotate the secret with dual-accept

Testing procedure

  • Send a tampered payload and assert 401

Troubleshooting

Signature never matches

A body parser re-serialised the payload. Verify against raw bytes.