Skip to content
GuidesAPI v1admin-sdk 1.1.52Search docs⌘K
Webhooks · Verify signatures
Guides / Webhooks

Verify signatures

Every delivery is signed. Check the signature before you trust the body; anyone can post to your URL.

How it's signed

X-Inkress-Webhook-Signature is the HMAC-SHA256 of the raw request body, keyed with the signing secret and base64 encoded.

EndpointSigning secret
Added by a merchant or for oneThat merchant's client secret, from API keys.
Registered by an appThe app's webhook secret, whsec_…, from the app's page.

Check it

  • Read the raw body before any JSON parser touches it. Re-encoding changes the bytes.
  • Compute the HMAC-SHA256 with your secret, base64 encode it, and compare with the header in constant time.
  • Reject the request with 400 if they differ.

With the Node SDK (1.1.52), inkress.webhookUrls.verify(body, signature, secret) does the comparison and throws when it fails.

Was this page helpful?Updated Oct 8, 2026