basalt / webhooks/src / signPayload
Function: signPayload()
> signPayload(body, secret, timestampSeconds): string
Defined in: webhooks/src/deliver.ts:60
Signs a payload the Stripe way: t=<unix>,v1=<hmac-sha256(t.body)>. The receiver recomputes the HMAC over timestamp.body and compares in constant time, rejecting stale timestamps to stop replays.
Pass several secrets (current first) to emit one v1= entry per secret — what the deliverer does during a secret rotation's grace window, so a receiver still verifying with the previous secret keeps accepting.
Parameters
body
string
secret
string | readonly string[]
timestampSeconds
number
Returns
string