Skip to content

basalt / webhooks/src / verifySignature

Function: verifySignature() ​

> verifySignature(header, body, secret, toleranceSeconds?, nowSeconds?): boolean

Defined in: webhooks/src/deliver.ts:80

Verifies a signature header (for tests and receiver SDKs). The header may carry several v1= entries — a sender rotating its secret signs with both the new and the old one — and is valid when ANY of them matches, as Stripe receivers do. Unknown schemes are ignored; a malformed header (no/duplicate t, no v1) is false, and so is an empty, unset or shorter-than- MIN_WEBHOOK_SECRET_LENGTH secret.

Throws a RangeError when toleranceSeconds is not a finite number ≥ 0 or nowSeconds is not finite (e.g. Number(process.env.UNSET) → NaN): such a value would otherwise make every timestamp "fresh" and silently disable replay protection. That is a configuration bug, never a verdict on a request.

Parameters ​

string

body ​

string

secret ​

string

toleranceSeconds? ​

number = 300

nowSeconds? ​

number = ...

Returns ​

boolean

Released under the MIT License.