v6.4.0
Highlights
This release documents a new endpoint related to rotating (or creating, if one is not already set) a secret key that may be used to authenticate Webhook calls. This function is called rotateWebhookSecret() (PUT /v2/webhooks/rotate-secret) and may only be called by an admin or owner of the respective Organization. If set, Webhook deliveries will include a new x-webhook-signature header with an HMAC-256 hash of the call payload's body field, represented as a JSON-string. Developers may use this to validate incoming Webhook payloads using code such as the following:
// NOTE: Hash the body field INSIDE the payload. In many frameworks the payload is also called
// "body", so be careful to avoid confusion.
const jsonBody = JSON.stringify(req.body.body);
const hash = createHmac('sha256', SECRET_KEY).update(jsonBody).digest('hex');
if (hash !== req.headers['x-webhook-signature']) {
// Handle error here
}
// It is important to return a 200 status code anyway, to avoid the sender trying to resend
// the same data.
res.status(200).send();