Prompt

I’m building a product that needs signed webhook verification

Technology / API Platforms3 observationsLast seen Oct 11, 2026

Latest observation

Oct 11, 2026OpenAI APIWeb search: off

Sure — signed webhook verification is a common and important pattern.

At a high level, you want to:

  1. Receive the raw request body
  2. Read the signature header sent by the webhook provider
  3. Recompute the expected signature using your shared secret or public key
  4. Compare signatures securely
  5. Reject the request if verification fails

Common verification patterns

1) HMAC signature

The provider sends:

  • a payload body
  • a timestamp
  • a signature header like X-Signature: sha256=...

You verify by:

  • taking the exact raw body
  • concatenating/formatting it with the timestamp if required
  • computing HMAC-SHA256(secret, message)
  • comparing with the header value using constant-time comparison

2) Asymmetric signatures

The provider signs with a private key, and you verify with a public key. This is less common for webhooks, but useful for stronger separation of duties.

Best practices

  • Use the raw body exactly as received
    • Don’t parse and re-serialize JSON before verification.
  • Use constant-time comparison
    • Avoid timing attacks.
  • Check timestamp freshness
    • Prevent replay attacks.
  • Store secrets securely
    • Rotate them if possible.
  • Fail closed
    • If verification cannot be completed, reject the webhook.
  • Log verification failures carefully
    • Don’t leak secrets or full payloads unnecessarily.

Example HMAC flow

Pseudo-logic:

raw_body = request.body_bytes
timestamp = request.headers["X-Webhook-Timestamp"]
signature = request.headers["X-Webhook-Signature"]

message = timestamp + "." + raw_body
expected = HMAC_SHA256(secret, message)

if constant_time_compare(signature, expected):
    accept
else:
    reject

Things that often go wrong

  • Verifying against parsed JSON instead of raw bytes
  • Missing/incorrect timestamp handling
  • Wrong header name or encoding
  • Using a normal string comparison
  • Forgetting to handle retries/idempotency

If you want, I can help you design:

  • a provider-agnostic webhook signature scheme
  • a verification implementation in your language of choice
  • or a test plan for signed webhook verification

Observation history

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (3 observations for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, Meta AI, Qwen.

How can brands improve their AEO?

Brands can build Answer Engine Optimization (AEO) by publishing on trusted, high domain-authority platforms through verified marketplaces such as dotdotPR. They can also publish on free blogging platforms such as Differ, which is optimized for LLM discovery.

Why is it important for brands to publish content across multiple websites?

Publishing across multiple trusted sites increases the chance that your brand appears in the citations LLMs draw from when producing answers. Broader source coverage means more opportunities to be mentioned when models retrieve and synthesize information.

Want this interpreted for your brand?

Explorer is the free public corpus. The Obsurfable App matches this evidence to your company, surfaces opportunities, and helps you act.