Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use the signature scheme your webhook provider supports. HMAC-SHA256 is a straightforward choice when sender and receiver can safely share a secret. A public-key signature such as Ed25519 lets the sender keep the signing key private while receivers verify with a public key. Either way, verify the exact request bytes, check freshness when signed timestamps are available, and prevent duplicate processing.

How HMAC and public-key signatures differ

Both schemes let a receiver check that a webhook was authenticated with the expected key and that its signed content has not changed. Their key-sharing models are different.

Decision point HMAC shared secret Public-key signature
Who holds which key? The sender and receiver both hold the signing secret. The sender holds the private signing key; the receiver verifies with the public key.
Who can create a valid signature? Every holder of the secret can generate a valid message authentication code (MAC). A receiver with only the public key can verify signatures but cannot create them.
Operational considerations Simple and widely available when the provider supports it, but the shared secret must be protected on both sides. Requires the appropriate key pair, an authentic public key, and a maintained verification library.
Performance Svix describes symmetric signatures as faster in its own implementation. Svix describes asymmetric operations as more CPU-intensive in its own implementation. These are vendor-specific descriptions, not general benchmarks.
Best fit Use when sharing and protecting the secret is manageable and the provider offers HMAC. Consider when receivers should verify without receiving a signing secret or when the trust boundary favors public verification.

The Standard Webhooks specification uses HMAC-SHA256 and Ed25519 as examples of symmetric and asymmetric signing. Its HMAC secrets are specified as random values from 24 to 64 bytes; that range is part of this specification, not a universal requirement. Its Ed25519 method uses a key pair.

Choose the scheme your provider actually sends

There is no universal webhook signature format. Providers can differ in algorithm, header names, encoding, and the exact message they sign. Follow the provider’s official verification instructions and use its SDK when available rather than substituting a generic implementation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • GitHub: GitHub recommends the X-Hub-Signature-256 header, which carries an HMAC-SHA256 signature made with the webhook secret and payload. Its cited guidance does not describe Ed25519 as a GitHub webhook-signature option. See GitHub’s validation guide.
  • Standard Webhooks: The specification describes webhook-id, webhook-timestamp, and webhook-signature. Its examples use HMAC-SHA256 with version label v1 and Ed25519 with v1a. See the specification.

Svix documents support for symmetric and asymmetric schemes and describes its own symmetric option as the default. That product-specific default is not a general rule for other providers. Its webhook repository README describes implementation-specific performance trade-offs.

How to verify a webhook safely

  1. Confirm the provider’s format. Check its official instructions for the algorithm, signature header, key format, signed fields, and message construction. Prefer the provider’s maintained SDK if one is available.
  2. Keep the raw request body. Verify the original bytes before parsing or acting on the event. Parsing JSON and serializing it again can alter whitespace or encoding, producing different bytes and an invalid signature. Svix discusses this raw-body requirement in its Ruby receiving guide.
  3. Calculate and compare the signature correctly. For HMAC, calculate the expected MAC using the documented secret and compare it with a constant-time function provided by your platform. Avoid ordinary string equality when a timing-safe comparison is available. For public-key verification, use a maintained cryptographic library and make sure the public key came from an authentic provider channel.
  4. Check signed timestamps when provided. Reject deliveries outside an appropriate freshness window. Choose that tolerance in light of the provider’s documented behavior and your integration’s needs.
  5. Make processing idempotent. Record unique delivery or event IDs and ensure that receiving the same business event again does not repeat its effects. A valid signature proves the message was signed; it does not prove it has never been seen before.
  6. Accept durably before acknowledging. Return the response expected by the provider only after the event has been durably accepted. Account for its retry behavior: a retry can be a repeat delivery of the same event, not a new business event.

Prevent replays and handle retries

A captured, correctly signed request can be sent again, so signature verification alone does not stop replay. A signed timestamp lets a receiver limit how old a delivery may be; a unique ID lets it identify a delivery already accepted. Standard Webhooks recommends timestamp freshness checks and using the unique ID as an idempotency key. GitHub recommends using X-GitHub-Delivery to identify deliveries and help prevent replayed deliveries from being processed more than once; see its webhook best practices.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Keep the provider’s retry policy in view when choosing freshness limits and acknowledgement behavior. A retry may arrive after a temporary outage, while an attacker may also replay a captured request. Freshness checks and durable deduplication address different parts of that problem; neither changes the need to verify the signature first.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Plan key rotation before an incident

Rotation needs to account for senders and receivers changing keys at different times. The Standard Webhooks specification supports multiple signatures during an overlap period, allowing a receiver to accept signatures made with old and new keys while transitioning. Configure the overlap according to the provider’s documented behavior, then retire the old key when the transition ends. If a key is compromised, respond promptly rather than waiting for the normal rotation window.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

For HMAC, every system that needs to verify during the transition must receive the relevant secret securely. For a public-key scheme, receivers need an authentic replacement public key while the sender protects the corresponding private key. In both cases, restrict access to key material and avoid logging secrets or private keys.

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.