Skip to content

basalt / webhooks/src / signPayload

Function: signPayload() ​

> signPayload(body, secret, timestampSeconds): string

Defined in: webhooks/src/deliver.ts:60

Signs a payload the Stripe way: t=<unix>,v1=<hmac-sha256(t.body)>. The receiver recomputes the HMAC over timestamp.body and compares in constant time, rejecting stale timestamps to stop replays.

Pass several secrets (current first) to emit one v1= entry per secret — what the deliverer does during a secret rotation's grace window, so a receiver still verifying with the previous secret keeps accepting.

Parameters ​

body ​

string

secret ​

string | readonly string[]

timestampSeconds ​

number

Returns ​

string

Released under the MIT License.