Skip to content

Function: verifyWebhookSignature() ​

ts
function verifyWebhookSignature(options): Promise<boolean>;

Defined in: src/webhooks/verify.ts:104

Whether the body carries a signature this secret produces.

Answers false for every way a delivery can fail to be trustworthy — no header, an algorithm other than sha256, a digest that is not hexadecimal, a digest of the right shape and the wrong value — because a handler's response to all four is the same, and telling them apart to the caller would tell them apart to whoever is probing the endpoint.

Throws only on a mistake of yours: an empty secret would make every delivery verify against a value an attacker can compute, so it is a programming error rather than a failed check.

Parameters ​

ParameterType
optionsVerifyWebhookSignatureOptions

Returns ​

Promise<boolean>