Skip to main content
You should verify the authenticity of each webhook request using the following headers.

Step 1: Prepare the signed_payload string

Concatenate the following to create the signed_payload string:
  • The timestamp (as a string)
  • A . character
  • The request body (as a string)

Step 2: Compute the expected_signature

Compute the expected_signature using the HMAC-SHA256 hash function. Use the webhook destination’s signing_secret as the key, and use the signed_payload string as the message.
For a directly configured destination, the signing_secret is returned when the destination is created from Webhooks. For a partner app, reveal or rotate the separate app signing secret from Created Apps. See Partner webhooks.

Step 3: Compare the signatures

Compare the expected_signature to the X-Subtotal-Signature. To prevent replay attacks, compare the received timestamp to the current time and reject requests outside your tolerance window. To protect against timing attacks, use a constant-time string comparison.