Webhooks · Verify signatures
Guides / Webhooks
Verify signatures
Every delivery is signed. Check the signature before you trust the body; anyone can post to your URL.
How it's signed
X-Inkress-Webhook-Signature is the HMAC-SHA256 of the raw request body, keyed with the signing secret and base64 encoded.
| Endpoint | Signing secret |
|---|---|
| Added by a merchant or for one | That merchant's client secret, from API keys. |
| Registered by an app | The app's webhook secret, whsec_…, from the app's page. |
Check it
- Read the raw body before any JSON parser touches it. Re-encoding changes the bytes.
- Compute the HMAC-SHA256 with your secret, base64 encode it, and compare with the header in constant time.
- Reject the request with
400if they differ.
With the Node SDK (1.1.52), inkress.webhookUrls.verify(body, signature, secret) does the comparison and throws when it fails.
Was this page helpful?Updated Oct 8, 2026