Zum Hauptinhalt springen
MD to PDF

API-Dokumentation

Webhook signatures

Auf dieser Seite

Operate

Verify webhook signatures

Verify signed webhook bodies before parsing or applying side effects.

Preserve the raw body

Read the timestamp and v1 digest from X-MD2PDF-Signature. Build the signed payload from the timestamp, a period, and the exact raw HTTP body.

Signed payload
<unix-seconds>.<exact-raw-request-body>

Verify before processing

Compute HMAC-SHA256 with the current whsec_ secret and compare lowercase hexadecimal digests using a constant-time operation. Reject stale timestamps before processing the event.

  • Do not parse and reserialize JSON before verification.
  • Use constant-time comparison.
  • Keep the current and immediately previous secret during a controlled rotation window.

API-Zugriff wird geprüft

Aktivierungsstatus wird geladen.