Skip to main content

Verifying Webhook Signatures

Every webhook Novacrust sends to your configured webhookUrl includes an X-Novacrust-Signature and X-Novacrust-Timestamp header, computed with the webhook secret shown in your Dashboard under Settings → Webhooks. The signature is an HMAC-SHA256 of {timestamp}.{raw JSON body}, keyed with your webhook secret, and sent as sha256={hex digest}. Always verify a delivery before trusting its payload, and use the raw request body exactly as received — re-serializing after JSON parsing can alter key ordering or whitespace and produce a signature mismatch.

Node.js

Webhook Verification

Python