Skip to content

v6.4.0

Choose a tag to compare

@crrobinson14 crrobinson14 released this 10 Dec 01:05
· 89 commits to main since this release

Highlights

This release documents a new endpoint related to rotating (or creating, if one is not already set) a secret key that may be used to authenticate Webhook calls. This function is called rotateWebhookSecret() (PUT /v2/webhooks/rotate-secret) and may only be called by an admin or owner of the respective Organization. If set, Webhook deliveries will include a new x-webhook-signature header with an HMAC-256 hash of the call payload's body field, represented as a JSON-string. Developers may use this to validate incoming Webhook payloads using code such as the following:

    // NOTE: Hash the body field INSIDE the payload. In many frameworks the payload is also called
    // "body", so be careful to avoid confusion.
    const jsonBody = JSON.stringify(req.body.body);
    const hash = createHmac('sha256', SECRET_KEY).update(jsonBody).digest('hex');
    if (hash !== req.headers['x-webhook-signature']) {
      // Handle error here
    }

    // It is important to return a 200 status code anyway, to avoid the sender trying to resend
    // the same data.
    res.status(200).send();