basalt / webhooks/src / verifySignature
Function: verifySignature()
> verifySignature(header, body, secret, toleranceSeconds?, nowSeconds?): boolean
Defined in: webhooks/src/deliver.ts:80
Verifies a signature header (for tests and receiver SDKs). The header may carry several v1= entries — a sender rotating its secret signs with both the new and the old one — and is valid when ANY of them matches, as Stripe receivers do. Unknown schemes are ignored; a malformed header (no/duplicate t, no v1) is false, and so is an empty, unset or shorter-than- MIN_WEBHOOK_SECRET_LENGTH secret.
Throws a RangeError when toleranceSeconds is not a finite number ≥ 0 or nowSeconds is not finite (e.g. Number(process.env.UNSET) → NaN): such a value would otherwise make every timestamp "fresh" and silently disable replay protection. That is a configuration bug, never a verdict on a request.
Parameters
header
string
body
string
secret
string
toleranceSeconds?
number = 300
nowSeconds?
number = ...
Returns
boolean