{"slug":"agent402-tools-api-webhook-verify-2c44ab","title":"Verify a webhook's HMAC signature against the correct per-provider scheme","host":"agent402.tools","method":"POST","resource":"https://agent402.tools/api/webhook-verify","category":"commerce","description":"Verify a webhook's HMAC signature against the correct per-provider scheme: GitHub (X-Hub-Signature-256, sha256=hex), Stripe (Stripe-Signature t/v1 over \"<t>.<body>\" with replay tolerance), Shopify (X-Shopify-Hmac-Sha256, base64), Slack (X-Slack-Signature, v0:<ts>:<body> with replay tolerance). Const","price_listed":0.001,"price_asked":0.001,"state":"answering","state_label":"Answering","checks_7d":1,"answered_7d":1,"latency_ms_median":949,"reported_calls_30d":4,"reported_payers_30d":1,"networks":["algorand:wGHE2Pwdvd7S12BL5FaOP20EGYesN73ktiC1qzkkit8=","eip155:10","eip155:1329","eip155:137","eip155:143","eip155:42161","eip155:42220","eip155:43114","eip155:4663","eip155:8453","solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp","stellar:pubnet"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"body":{"payload":"{\"hello\":\"world\"}","provider":"github","secret":"it's a secret","signature":"sha256=8d4063f0a81aa1531d9891a028a68cf2bb537ecdf0e82557674d71e168d570f9"},"bodyType":"json","method":"POST","type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"body":{"properties":{"payload":{"description":"the RAW request body string, byte-for-byte as received (never a re-serialized object)","type":"string"},"provider":{"description":"github | stripe | shopify | slack","type":"string"},"secret":{"description":"the provider signing secret (never echoed back)","type":"string"},"signature":{"description":"the signature header value, with or without its scheme prefix (sha256= / v0= / t=...,v1=...)","type":"string"},"timestamp":{"description":"provider timestamp, required for stripe + slack (stripe may be parsed from a t= element in the signature)","type":"string"},"toleranceSeconds":{"description":"max timestamp age for stripe/slack replay protection (default 300; 0 skips the age check)","type":"number"}},"required":["provider","payload","secret","signature"]},"bodyType":{"enum":["json","form-data","text"],"type":"string"},"method":{"enum":["POST"],"type":"string"},"type":{"const":"http","type":"string"}},"required":["type","method","bodyType","body"],"type":"object"},"output":{"properties":{"example":{"properties":{"provider":{"type":"string"},"reason":{"type":"string"},"scheme":{"type":"string"},"valid":{"type":"boolean"}},"required":["valid","provider","scheme","reason"],"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[{"day":"2026-09-24","reachable":true,"status":402,"valid_402":true,"asked_usdc":0.001,"price_match":true,"latency_ms":949,"error":null}],"description_full":"Verify a webhook's HMAC signature against the correct per-provider scheme: GitHub (X-Hub-Signature-256, sha256=hex), Stripe (Stripe-Signature t/v1 over \"<t>.<body>\" with replay tolerance), Shopify (X-Shopify-Hmac-Sha256, base64), Slack (X-Slack-Signature, v0:<ts>:<body> with replay tolerance). Constant-time comparison; the secret is never echoed. Pass the RAW request body string - signatures are over the raw bytes. Deterministic.","last_updated":"2026-09-21T11:06:58.404Z","schemes":["exact","upto"]}