Skip to content

VerifyWebhookRequestOptions

Defined in: packages/webhook/src/security/verify-webhook-request.ts:29

Options for verifyWebhookRequest. algorithm, signatureHeader, and signaturePrefix must match the sender’s WebhookConfig, so the same object can be passed to both.

  • Pick<WebhookConfig, "algorithm" | "signatureHeader" | "signaturePrefix">

optional algorithm?: "sha256" | "sha1"

Defined in: packages/webhook/src/types/webhook.types.ts:23

WebhookConfig.algorithm


optional signatureHeader?: string

Defined in: packages/webhook/src/types/webhook.types.ts:24

WebhookConfig.signatureHeader


optional signaturePrefix?: string

Defined in: packages/webhook/src/types/webhook.types.ts:25

WebhookConfig.signaturePrefix


optional toleranceMs?: number

Defined in: packages/webhook/src/security/verify-webhook-request.ts:40

How far the signed time may be from the receiver’s clock, in either direction, in milliseconds: a finite number of 0 or more. Defaults to 300000 (5 minutes). Signed times have one-second resolution, so a request up to a second older than this can still pass.