Skip to main content
Every delivery carries a signature. Verify it before you trust the payload — your endpoint is a public URL, and anything on the internet can post to it.

The header

It is an HMAC-SHA256 of the raw request body, keyed with your webhook secret, encoded as hexadecimal. Kira gives you the secret when your endpoint is registered. Keep it out of your source tree, the same as your API key.

Verifying it

Compute the same digest over the body you received and compare it with the header.

Two things that break verification

Sign the raw body, not a re-serialised object. If your framework parses the JSON and you re-encode it to verify, a different key order or spacing produces a different digest and every delivery fails. Capture the raw bytes before parsing. Compare in constant time. crypto.timingSafeEqual and hmac.compare_digest above exist for this. A plain === on a secret-derived value leaks information about it.

When it does not match

Reject the request and answer an error. Do not process the payload, and do not retry on your side — a mismatched signature means the delivery did not come from Kira, or the body was altered on the way.