Observed Signal · Aug 10, 2026 · Technical Guide · Source: DEV Community · Impact: 1/5 · Sentiment: Positive
Validate GitHub Webhooks with HMAC in PHP & Node.js
This technical guide explains how to validate GitHub webhooks using HMAC SHA-256 in PHP and Node.js. It provides minimal-checklist rules (preserve raw body, reject empty secret, validate X-Hub-Signature-256, compute HMAC, perform constant-time comparison) and complete example implementations: PHP using hash_hmac() and hash_equals(), and Node.js using createHmac() and timingSafeEqual(). The article also covers production recommendations such as preserving the raw request body, idempotency via X-GitHub-Delivery, filtering by X-GitHub-Event, limiting body size, queueing heavy work, never logging secrets, and adding business-level authorization checks. A public test vector and a GitHub repository with examples and tests are provided.
Practical developer security guidance with direct operational value but limited broad impact on the AdTech industry.
Track GitHub Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- The article demonstrates validating GitHub webhooks with HMAC SHA-256 in PHP and Node.js.
- PHP example uses hash_hmac() to calculate the signature and hash_equals() for constant-time comparison.
- Node.js example uses createHmac() and timingSafeEqual(); it validates buffer lengths before timingSafeEqual to avoid exceptions.
- Minimum checklist: read raw body, reject empty secret, validate X-Hub-Signature-256 format, compute HMAC, compare in constant time, reject invalid signatures before processing.
- Production recommendations include preserving raw body, idempotency via X-GitHub-Delivery, filtering X-GitHub-Event, queuing heavy work, and never logging the secret.
Connected Companies & Entities
1 Entity mapped“When delivering a webhook, GitHub calculates an HMAC using the original request body, the secret configured on the webhook, and the SHA-256 ...”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Verify Webhooks Using HMAC Signatures
This technical how-to explains how to secure webhook endpoints by verifying incoming requests with HMAC signatures. It describes the shared-secret HMAC-SHA256 flow used by providers (e.g., GitHub, Stripe, Slack), shows example signature header formats, and provides concrete implementation samples in Node.js (Express) and Python (FastAPI). The guide stresses verifying raw request bytes, using timing-safe comparisons to avoid timing attacks, and validating timestamps to prevent replay attacks. It also highlights common mistakes (parsing before verification, hardcoding secrets) and recommends storing secrets in environment variables and rotating them if needed.
How to Verify Shopify Webhooks Correctly
A technical how-to explaining correct verification of Shopify webhooks to prevent spoofing, replay attacks, and downstream data corruption. The article details Shopify's signing flow (HMAC-SHA256 of the raw request body, base64-encoded into the X-Shopify-Hmac-SHA256 header), provides ready-to-drop Node.js and Python verification examples, and lists common implementation mistakes (parsing before verification, insecure string comparisons, no replay protection, missing shop-domain validation, secrets in code). A production checklist covers transport (HTTPS/TLS), raw-body buffering, constant-time comparison, timestamp/deduplication protections, secret management, immediate 2xx acknowledgement with asynchronous processing, and reliability practices such as dead-letter queues.
Turning GitHub into a Headless CMS
The author describes a practical approach to using GitHub as a headless CMS for a PHP micro-framework website (PointArt). The site consumes a local database that is kept in sync with GitHub via webhooks: Releases drive an incremental upsert/delete workflow for the changelog, while pushes trigger a full re-fetch of CONTRIBUTING.md (roadmap) from GitHub's raw CDN and a delete+re-insert sync. The guide covers verifying GitHub's X-Hub-Signature-256 (HMAC-SHA256) over the raw request body, handling ping events, idempotent delete+insert patterns to tolerate retries, and operational gotchas such as initial backfill and API rate limits.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
