Verifying webhooks
Maintain security with verified transmissions
To verify that a webhook was actually sent by Noyo, every payload is signed with a signature that is passed through as the HTTP header. Here’s how to create a secret token and signature then confirm credentials.
Create a secret token for your subscription
You’ll create your secret token when you create the subscription in Command Center. You will not be able to retrieve this secret after creating it.
Generate a signature
The signature is hex encoded and can be replicated by applying HMAC-SHA-256 to the body of the webhook with your webhook key.
Confirm the signature
Webhook signatures are sent in the x-noyo-signature
header. You can verify that Noyo sent the event by comparing the signatures.
Was this page helpful?