verifyWebhookRequest
verifyWebhookRequest(
headers,body,secret,options?):Result<VerifiedWebhookRequest,WebhookVerificationError>
Defined in: packages/webhook/src/security/verify-webhook-request.ts:145
Checks that a webhook request came from a k-msg sender that holds secret
and was signed recently.
It verifies the signature header, an HMAC of <X-Webhook-Timestamp>.<body>,
in constant time, then checks that the signed time is within toleranceMs
of now. A request that passes can still be a repeat: webhooks are delivered
at least once, so skip event ids you have already processed.
Parameters
Section titled “Parameters”headers
Section titled “headers”The request headers.
The raw request body, preferably its bytes, before any decoding or JSON parsing.
secret
Section titled “secret”string
The endpoint’s signing secret (or the sender’s shared
secretKey).
options?
Section titled “options?”VerifyWebhookRequestOptions = {}
Returns
Section titled “Returns”Result<VerifiedWebhookRequest, WebhookVerificationError>
The signed time, or a WebhookVerificationError whose
code says which check failed.
Throws
Section titled “Throws”TypeError when secret is empty, and RangeError when
toleranceMs is negative, NaN, or infinite.
Example
Section titled “Example”const body = await request.arrayBuffer();const verified = verifyWebhookRequest( request.headers, body, env.WEBHOOK_SECRET,);if (verified.isFailure) { return new Response(verified.error.code, { status: 401 });}const event = JSON.parse(new TextDecoder().decode(body));