Releases: edilec/webhook-signature-verifier
Release list
Webhook Signature Verifier v0.1.0
Webhook Signature Verifier v0.1.0 is a public MIT command-line tool and Node library for checking supplied webhook delivery fixtures against six documented signature schemes. It verifies the exact body bytes, timestamp tolerance and a declared duplicate policy. A run can pass, fail or remain incomplete when evidence is unavailable; it does not execute a receiver or send network requests.
The included synthetic suite covers 11 declared deliveries: six accepted and five refused, with no undetermined deliveries. Published GitHub and Standard Webhooks signing examples are included alongside local synthetic fixtures. The suite is an example of the tool's behavior, not evidence about Edilec or a client's production webhook traffic.
Install from the public GitHub source with npm install github:edilec/webhook-signature-verifier, then run npx webhook-signature-verifier --suite path/to/your/suite.json. To run the included synthetic example, clone the repository and use npm run example from its root. The package is not published to npm. Node.js 22 or newer is required.
Source and limitations · Related Edilec guide to idempotent webhook processing
Maintained by Edilec Private Limited. This release description was drafted with AI assistance and checked against the public source, tests and synthetic examples.