Free tools Windows power users keep installed
One-click scans. No signup required.
Webhook verification is provider-specific: Slack, GitHub, Microsoft Teams, and Telegram Gateway use HMAC-based methods, while Google Chat authenticates inbound interactions with a bearer token. Verify the request using the provider’s documented inputs before acting on it; parsing and reserializing a body can invalidate a signature. This guide covers these five methods, not every chat platform: the current Discord procedure is not established here.
How the five methods differ
A webhook signature is usually a cryptographic value calculated from a secret and specified request data. The receiver repeats that calculation and compares the result with the value sent by the provider. Google Chat’s documented interaction flow is different: it authenticates a bearer token and its claims rather than signing the request body with an HMAC.
| Provider and request | Verification method | Input or token to verify | Replay and duplicate handling |
|---|---|---|---|
| Slack requests to an app | HMAC-SHA256 with an app signing secret | A versioned string incorporating the timestamp and request body; signature arrives in X-Slack-Signature |
The signed timestamp supports freshness checks and replay defense; use a defined age window |
| GitHub webhooks | HMAC-SHA256 with the configured webhook secret | Exact payload bytes; the result is sent in X-Hub-Signature-256 with a sha256= prefix |
The documented signature scheme does not establish timestamp freshness; use event IDs or equivalent idempotency controls |
| Microsoft Teams outgoing webhooks | SHA-256 HMAC, as identified by Microsoft Learn | Exact signed input and header encoding are not established here; follow the current Microsoft documentation | Freshness semantics are not established here |
| Google Chat interactions sent to an app | Bearer-token authentication | An ID token for an HTTP endpoint URL audience, or a JWT for a project-number audience configuration | Validate the token and its configured audience; an HMAC body-signature freshness rule does not apply to this method |
| Telegram Gateway delivery reports | HMAC-SHA256 | SHA-256 of the API token is the HMAC key; sign the timestamp, a line feed, and exact raw POST body; compare with the hexadecimal value in X-Request-Signature |
Check timestamp freshness and make processing idempotent; Telegram says reports may be retried up to 10 times |
These methods are not interchangeable. A verifier must use the provider’s header names, key derivation, signed input, encoding, and token-audience rules rather than applying one platform’s code to another.
How to verify a Slack webhook signature
Slack signs requests using an app-specific signing secret and sends the signature in X-Slack-Signature. The signature is tied to a timestamp, so verifying the signature and rejecting stale timestamps work together to limit replay attempts. Slack’s signed-secret approach has replaced older verification tokens, which are deprecated.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
- Read the timestamp header and signature header from the incoming request. Treat both as untrusted input and reject missing or malformed values.
- Retain the exact request body bytes. Build Slack’s versioned signature base string from the timestamp and body, then calculate HMAC-SHA256 using the app’s signing secret.
- Compare the computed signature with the supplied signature using a constant-time comparison. Reject a mismatch.
- Reject requests whose timestamp falls outside your configured short recency window. Keep the server clock synchronized so valid requests are not rejected due to clock drift.
- Only after verification, parse the body and route the event. Use a stable event identifier or equivalent idempotency key when the event can be retried.
Slack documents signed requests for multiple app request types, including Events API requests, shortcuts, slash commands, and Slackbot MCP Client. Confirm that the endpoint you are securing uses this signed-request mechanism and its current documentation before implementing it.
How to validate a GitHub webhook signature
GitHub recommends HMAC-SHA256 in X-Hub-Signature-256. The header value has a sha256= prefix. GitHub also provides the older X-Hub-Signature HMAC-SHA1 header for legacy compatibility, but recommends SHA-256 instead.
- Configure a high-entropy webhook secret and keep it on the server. Do not expose it in client-side code or logs.
- Capture the exact payload bytes received by the endpoint before JSON parsing or any middleware that could transform the body.
- Calculate HMAC-SHA256 over those bytes using the configured secret. Format the expected value as the documented SHA-256 header value, including the
sha256=prefix. - Validate the header format, then compare the expected and received values with a constant-time comparison. Reject missing, malformed, or mismatched signatures before processing the event.
- Use a GitHub delivery or event identifier to make processing idempotent. The HMAC authenticates the payload but, by itself, does not establish that a delivery is fresh.
GitHub warns that proxies and body parsing or re-encoding can change the signed input. A correctly configured HMAC will still fail if the receiver calculates it over bytes different from the original payload.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
What is established for Microsoft Teams outgoing webhooks
Microsoft Learn identifies SHA-256 HMAC authentication for Teams outgoing webhooks and provides validation code. The available documentation details do not establish the exact signed bytes, header encoding, or freshness semantics here. Do not infer those details from Slack, GitHub, or another service.
For an implementation, follow the current Microsoft Learn instructions for the specific Teams outgoing-webhook flow and reproduce its input construction and comparison exactly. Until those details are confirmed, the supported claim is the algorithm family—SHA-256 HMAC—not a copy-and-paste verification formula.
How to authenticate Google Chat interaction requests
Google Chat sends an Authorization: Bearer token with HTTPS requests to an app’s HTTP endpoint. This is request authentication, not an HMAC signature over the body. The verification procedure depends on the authentication audience configured for the app:
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
- For an HTTP endpoint URL audience, verify the token as an ID token.
- For a project-number audience configuration, verify it as a JWT.
A custom HTTP server can validate the token with Google’s API client libraries or JWT validation. Cloud Run and Cloud Functions can perform verification through Cloud IAM when the Google Chat service account is authorized as an invoker. If token verification fails, return HTTPS 401 rather than processing the request.
Do not confuse this with a Google Chat incoming webhook. An incoming webhook is a posting URL containing a unique secret token, used to send messages into a space; it is not the bearer-token authentication method used to verify inbound interaction requests to an app.
Recommended Free Tools
How to verify a Telegram Gateway delivery report
Telegram Gateway delivery reports include X-Request-Timestamp and X-Request-Signature. The calculation uses the API token to derive a key, then signs the timestamp and raw request body.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
- Read the timestamp and signature headers, rejecting missing or malformed values.
- Keep the exact raw POST body. Do not parse and serialize it before verification.
- Derive the HMAC key by calculating SHA-256 of the Telegram Gateway API token.
- Calculate HMAC-SHA256 over the timestamp, one line-feed character, and the exact raw body in that order.
- Compare the hexadecimal result with
X-Request-Signatureusing a constant-time comparison, and reject mismatches. - Check that the timestamp is within your configured freshness window. After verification, process the report idempotently.
Telegram says callback deliveries expect HTTP 200 and may be retried up to 10 times with increasing delays. Design the handler so a repeated delivery cannot apply the same state change more than once, and return the success or failure response appropriate to the verified result.
Why webhook signature verification fails
When a valid provider request is rejected, first check that the implementation follows that provider’s exact construction rather than assuming all HMAC webhooks sign the same value.
- The body changed before verification. JSON parsing and reserialization can alter whitespace, key order, or Unicode escaping. Capture raw bytes before body-parser middleware, proxies, or other transformations.
- The wrong input was signed. Some methods use the body alone; others incorporate a timestamp or use token claims rather than a body signature. Match the specified order and separators exactly.
- The secret or key derivation is wrong. Confirm the secret belongs to the correct app or endpoint, is read from server-side configuration, and is transformed only when the provider specifies a derivation step.
- The header format is mishandled. Check the precise header name, prefix, encoding, and case expectations; reject unexpected forms instead of silently normalizing them.
- The timestamp check is out of sync. Clock drift or an overly narrow age window can reject otherwise valid timestamped requests. Synchronize the server clock and set a deliberate freshness policy.
- A regular string comparison is used. Use a constant-time comparison for secret-dependent signature values to avoid leaking comparison progress.
- Processing happens before verification. Authenticate first, then parse or act on the request; otherwise a forged request may trigger side effects even if its signature later fails.
How to prevent replay and duplicate processing
Freshness checks and idempotency address separate risks. A timestamp limit can reject an old signed attempt when the provider includes a timestamp, but it does not by itself prevent a provider retry from delivering the same legitimate event again. Conversely, an event ID can prevent duplicate effects but does not make an unauthenticated request trustworthy.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
- For timestamped methods, validate timestamp freshness after checking the provider’s specified signature or token. Choose an age window appropriate to delivery behavior and maintain reliable clock synchronization.
- For methods without a documented freshness field, do not invent one or claim the body HMAC prevents replay. Authenticate the delivery, then apply idempotency using a stable provider event or delivery identifier where available.
- Record the idempotency key and the processing outcome atomically with the business change when possible. A retry should return the appropriate response without repeating a completed action.
- Verify before triggering side effects. HTTPS protects transport but does not, on its own, prove that a request came from the claimed provider.
Implementing verification in Node.js or Python
The safe implementation pattern in either language is to capture raw bytes at the HTTP framework boundary, select the exact provider-specific input, calculate or validate the provider’s credential, and perform a constant-time comparison before parsing or processing. Use the language’s cryptographic library rather than writing HMAC or JWT cryptography yourself.
Do not copy a generic HMAC snippet and merely change the secret. For GitHub, the signed input is the exact payload bytes; for Slack, the timestamp participates in a versioned base string; for Telegram Gateway, the key is derived from the API token and the signed input includes a timestamp, line feed, and raw body. Google Chat requires token and audience validation, while the precise Teams construction must come from Microsoft’s current instructions.
Keep secrets in server-side secret storage, avoid logging full authorization tokens or secrets, and test both valid and deliberately modified requests. A test that changes one body byte should fail verification; a stale timestamp should fail where freshness is required; and a repeated valid event should not repeat the same business action.
Does this cover every chat platform?
No. These procedures cover five documented chat-platform flows: Slack, GitHub webhooks, Microsoft Teams outgoing webhooks, Google Chat interactions, and Telegram Gateway delivery reports. The current Discord verification method is not established here, so it would be misleading to present this as an exhaustive guide to every chat platform.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

