Kb
Webhook signatures
Securely verify webhook authenticity.
(5.0)
Verification
We sign each webhook with X-GRD-Signature.
- Extract the signature from the
X-GRD-Signatureheader. - Compute HMAC-SHA256 of the request body using your signing secret.
- Compare timing-safe. Reject if mismatch or timestamp skewed.
See also: API reference.