Kb

Webhook signatures

Securely verify webhook authenticity.

(5.0)

Verification

We sign each webhook with X-GRD-Signature.

  1. Extract the signature from the X-GRD-Signature header.
  2. Compute HMAC-SHA256 of the request body using your signing secret.
  3. Compare timing-safe. Reject if mismatch or timestamp skewed.

See also: API reference.