Skip to main content
Every event delivery carries an X-Ingestly-Signature header computed with your organization’s webhook signing key. Verify it before you trust the body: anyone who learns your endpoint URL can send it a request, but only Ingestly holds the key.

The signature header

The signed payload is the timestamp, a period and the raw request body: {t}.{raw body}. The HMAC key is the whole signing key string as shown in the dashboard, whsec_ prefix included, encoded as UTF-8. Do not Base64-decode it.

Verifying a delivery

  1. Read the raw request body bytes before any framework parses them.
  2. Split the header on commas and take t and every v1.
  3. Reject the request when t is more than 5 minutes away from your clock, so a captured request cannot be replayed later.
  4. Compute the HMAC-SHA256 of {t}.{raw body} with your key, as lowercase hex.
  5. Accept the request when it equals any v1, comparing in constant time.
Verify the exact bytes you received. Parsing the JSON and serializing it again changes whitespace and key order, and the signature no longer matches.
A request with no X-Ingestly-Signature header did not come from an event subscription: Ingestly never sends an event unsigned. Reject it.

Node.js

Python

Rotating keys without downtime

While you rotate the signing key, every delivery is signed with both keys, one v1 each. The functions above accept a request when any v1 matches, so your endpoint keeps verifying with the old key until you deploy the new one. Complete the rotation only after the new key is live. The same header and the same check also cover the writes an HTTP Request node sends, except that a binary body is signed over its Base64 encoding.