Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallVerify a webhook against the original request body bytes and the sending provider’s exact signing scheme before parsing the payload or taking action. Preserve the raw body at the framework boundary, use the provider’s official SDK where available, and treat signature verification, replay checks, and duplicate-delivery handling as separate controls.
Use this verification sequence
- Read the provider’s current instructions. Identify the exact headers, signing input, digest format, secret, and any timestamp or delivery-ID rules. Do not assume one provider’s HMAC recipe applies to another.
- Capture the original request body. Keep the bytes as received until verification is complete. Parsing JSON and serializing it again can change whitespace, key order, or encoding and produce different bytes from those the provider signed. See the GitHub, Shopify, and Stripe guidance.
- Verify using the correct endpoint secret and provider method. Prefer the official SDK when one is available. If implementing verification yourself, match the provider’s signing input, algorithm, encoding, and any required prefix exactly.
- Reject invalid requests. Do not trust payload fields or trigger business actions unless verification succeeds. Use a constant-time or dedicated secure comparison function for secret-derived signatures; GitHub and Slack explicitly recommend secure comparison.
- Only then parse and process. Once authenticated, decode or parse the body and pass it to application logic.
Provider signing schemes are not interchangeable
The schemes below illustrate why a universal verifier is unsafe. The signing input, header format, digest encoding, and replay protections differ by provider. Follow the provider’s linked instructions for the endpoint and delivery type you use.
| Provider | What to verify | Timestamp and duplicate handling |
|---|---|---|
| GitHub | X-Hub-Signature-256 contains a hex HMAC-SHA256 digest prefixed with sha256=, computed over the payload contents using the configured secret. GitHub describes UTF-8 handling where applicable and recommends secure comparison. GitHub documentation |
The cited guide does not document a signed timestamp, so do not assume timestamp-based replay protection. A delivery ID can be used to deduplicate deliveries. GitHub documentation |
| Shopify | For HTTPS deliveries, X-Shopify-Hmac-SHA256 is a base64-encoded HMAC-SHA256 of the raw body, generated with the app client secret. Shopify says its Google Cloud Pub/Sub and Amazon EventBridge deliveries do not require this HMAC verification. Its React Router template authenticates automatically. Shopify documentation |
Use idempotent processing or persist X-Shopify-Webhook-Id to deduplicate deliveries. Shopify documentation |
| Slack | Use X-Slack-Request-Timestamp and X-Slack-Signature. Construct v0:<timestamp>:<raw-body>, HMAC-SHA256 it with the signing secret, then securely compare the hex digest with the value prefixed by v0=. Slack documentation |
Slack’s example rejects timestamps more than five minutes from local time. The timestamp is part of the signing base string; it does not eliminate the need to handle duplicate processing safely. Slack documentation |
| Stripe | Use the official SDK’s constructEvent() with the original request-body string, the Stripe-Signature header, and the endpoint secret. Stripe identifies body mutation and using the wrong endpoint secret as common verification failures. Stripe documentation |
Use Stripe’s documented verification method and endpoint configuration; do not substitute a different endpoint’s secret. The cited guide’s recipe is SDK-based rather than a general-purpose HMAC specification. Stripe documentation |
| Svix | Headers include Webhook-Id, Webhook-Timestamp, and Webhook-Signature. The signed content is <id>.<timestamp>.<raw-body>, using HMAC-SHA256. Svix Django guide and Svix Rails guide |
Svix libraries reject timestamps more than five minutes from current time. The message ID is part of the signed content and can also help identify duplicate messages. Svix Django guide |
Preserve the raw body in your framework
The framework’s parser and middleware order determine whether the original bytes are still available when verification runs. These are representative patterns, not complete recipes for every framework version or hosting platform; follow your provider’s current SDK and framework documentation.
Express and Node.js
Mount the provider’s verification route before general JSON parsing. Stripe warns that applying express.json() first can mutate the body; its webhook route must run before that middleware. Shopify’s manual Express example uses express.raw() and likewise requires verification before body parsers. Stripe documentation and Shopify documentation
Flask
For Slack, obtain the unparsed data with request.get_data() before accessing methods that deserialize the request. Use the exact Slack signing-base construction and timestamp check described in Slack’s guide. Slack documentation
Django
Svix’s Django example reads request.body and passes the payload and request headers to Webhook(secret).verify(payload, headers). Return a client error on verification failure and process only a verified message. Svix Django guide
Rank #2
Ruby on Rails
Svix’s Rails example reads request.body and passes the payload and request headers to its verifier before acting on the message. GitHub’s Ruby example rewinds and reads the body before JSON parsing. Svix Rails guide and GitHub documentation
Prevent replay and duplicate side effects
A valid signature establishes that a request matches a provider’s signing scheme; it does not by itself guarantee that the delivery is fresh, unique, or safe to apply twice. Slack states that its signature depends on the timestamp to protect against replay attacks. Slack documentation
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- Enforce freshness where the scheme supports it. Apply the provider’s documented timestamp check and tolerance. The Slack and Svix examples above specify their own five-minute checks; do not copy that tolerance to a provider whose instructions do not specify one.
- Make processing idempotent. Persist a stable delivery or message ID where available, or otherwise ensure retries cannot repeat irreversible actions. Shopify recommends idempotent processing or storing its webhook ID; GitHub delivery IDs can support deduplication. Shopify documentation and GitHub documentation
- Protect secrets. Keep high-entropy secrets out of source code, logs, and public issue reports. Confirm that the secret belongs to the endpoint that sent the request. A local Stripe CLI forwarding secret can differ from the dashboard endpoint secret. GitHub documentation and Stripe documentation
Debug a signature verification failure
Check these causes in order, without logging the secret or publishing sensitive request data:
- Wrong secret: confirm the secret is for the endpoint and environment that received the delivery. For Stripe, distinguish the local CLI secret from the dashboard endpoint secret. Stripe documentation
- Body changed before verification: ensure parsing, serialization, middleware, proxies, load balancers, or gateway templates have not altered the original body bytes. Confirm relevant headers also survive the path. GitHub documentation and Stripe documentation
- Wrong signing recipe: check the algorithm, exact signed input, header extraction, digest encoding, and version prefix against the provider’s guide. A hexadecimal digest is not interchangeable with a base64 digest. GitHub documentation, Shopify documentation, Slack documentation, and Svix Django guide
- Stale timestamp or clock skew: for a timestamped scheme, check system clock synchronization and use only the provider’s documented tolerance. Slack documentation and Svix Django guide
- Parsing too soon: move verification ahead of normal body parsing, then parse and process only after verification succeeds. Shopify documentation
For serverless deployments, gateways, and framework versions with body transformations, verify that the body delivered to the verifier is byte-for-byte equivalent to what the provider signed. Stripe documents raw-body approaches for Next.js and API Gateway/Lambda; middleware ordering and request-body APIs vary by deployment. Stripe documentation
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

