@sandsoftwaresolutions/webhooks
v0.1.0
Published
Web Crypto helpers for signing and verifying JSON webhooks.
Downloads
140
Maintainers
Readme
@sandsoftwaresolutions/webhooks
Web Crypto HMAC-SHA256 helpers for signing outbound webhooks and verifying incoming webhooks. Compatible with Node.js 18+, workers and modern browsers.
Install
npm install @sandsoftwaresolutions/webhooksVerify an incoming webhook
import { verify } from "@sandsoftwaresolutions/webhooks";
const rawBody = await request.text(); // Do not JSON.parse before verification
const valid = await verify(rawBody, request.headers.get("x-signature"), process.env.WEBHOOK_SECRET);
if (!valid) return new Response("Invalid signature", { status: 401 });Sign an outgoing webhook
import { sign } from "@sandsoftwaresolutions/webhooks";
const body = JSON.stringify({ event: "invoice.paid", data: invoice });
const signature = await sign(body, process.env.WEBHOOK_SECRET);sign(payload, secret) returns sha256=<hex>. verify(payload, signature, secret) returns a boolean and compares signatures safely. Use a long secret, preserve the exact raw request body, and add timestamp/replay protection in your webhook protocol.
