Observed Signal · May 2, 2026 · Technical Guide · Source: DEV Community · Impact: 1/5 · Sentiment: Positive

Verify Webhooks Using HMAC Signatures

Executive Signal Summary

This technical how-to explains how to secure webhook endpoints by verifying incoming requests with HMAC signatures. It describes the shared-secret HMAC-SHA256 flow used by providers (e.g., GitHub, Stripe, Slack), shows example signature header formats, and provides concrete implementation samples in Node.js (Express) and Python (FastAPI). The guide stresses verifying raw request bytes, using timing-safe comparisons to avoid timing attacks, and validating timestamps to prevent replay attacks. It also highlights common mistakes (parsing before verification, hardcoding secrets) and recommends storing secrets in environment variables and rotating them if needed.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Practical developer security guidance for webhook integrations; useful for engineering teams but not industry‑shifting.

SIGNAL RADAR

Track Stripe Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • HMAC verification uses a shared secret to compute HMAC-SHA256 over the request payload; providers include the resulting signature in a request header.
  • Common provider header formats: GitHub (X-Hub-Signature-256: sha256=...), Stripe (Stripe-Signature: t=...,v1=...), Slack (X-Slack-Signature: v0=...).
  • Code examples provided for Node.js (Express.raw, crypto.timingSafeEqual) and Python/FastAPI (hmac.compare_digest) to verify signatures using raw request bytes.
  • Timestamp checks (e.g., Stripe's 5-minute window) are recommended to mitigate replay attacks; the signed payload format may include the timestamp.
  • Common mistakes include parsing JSON before verification, using non-timing-safe string comparison, and storing secrets in code instead of environment variables.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: May 2, 2026
Original Coverage Title: “Webhook Security: How to Verify Incoming Requests with HMAC Signatures”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

InfrastructureAug 10, 2026

Validate GitHub Webhooks with HMAC in PHP & Node.js

This technical guide explains how to validate GitHub webhooks using HMAC SHA-256 in PHP and Node.js. It provides minimal-checklist rules (preserve raw body, reject empty secret, validate X-Hub-Signature-256, compute HMAC, perform constant-time comparison) and complete example implementations: PHP using hash_hmac() and hash_equals(), and Node.js using createHmac() and timingSafeEqual(). The article also covers production recommendations such as preserving the raw request body, idempotency via X-GitHub-Delivery, filtering by X-GitHub-Event, limiting body size, queueing heavy work, never logging secrets, and adding business-level authorization checks. A public test vector and a GitHub repository with examples and tests are provided.

Read assessment
Webhooks / Web App SecurityJun 5, 2026

How to Verify Shopify Webhooks Correctly

A technical how-to explaining correct verification of Shopify webhooks to prevent spoofing, replay attacks, and downstream data corruption. The article details Shopify's signing flow (HMAC-SHA256 of the raw request body, base64-encoded into the X-Shopify-Hmac-SHA256 header), provides ready-to-drop Node.js and Python verification examples, and lists common implementation mistakes (parsing before verification, insecure string comparisons, no replay protection, missing shop-domain validation, secrets in code). A production checklist covers transport (HTTPS/TLS), raw-body buffering, constant-time comparison, timestamp/deduplication protections, secret management, immediate 2xx acknowledgement with asynchronous processing, and reliability practices such as dead-letter queues.

Read assessment
InfrastructureJul 27, 2026

Successful HMAC Shows Signed Webhook Data Preserved

A production payment webhook was forwarded through an intermediary delivery layer (Adal Server → Adal CLI) and then verified by the final handler; the HMAC verification succeeded. The article explains that a successful HMAC check is strong evidence that the values included in the provider's signed message (often the raw request body, possibly plus a timestamp or selected metadata) were preserved end-to-end, but it does not prove that every HTTP header or transport detail remained byte-for-byte identical. The post emphasizes preserving raw request bytes, forwarding all signature-covered values, performing verification at the final trust boundary, using constant-time comparisons, and testing the full delivery route with real provider events.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.