Share a verifiable webhook check without exposing the source HMAC secret
Share a verifiable webhook check without exposing the source HMAC secret. IntegrityPhase verifies the signature, format and freshness, issuing a signed record. The recipient verifies the signature and its link to the original request. Example: a B2B order-acceptance webhook. The record does not prove fulfilment. Outside critical processes; EUR 100–200 operations; PL/CZ/FR legal entities; IntegrityPhase HMAC sources. Buy: https://api.integrityphase.com/mcp. Bazaar paid proxy unsupported.
Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.
Endpoint
POST https://api.integrityphase.com/verify/webhook-integrity
| Category | Everything else |
|---|---|
| Provider host | api.integrityphase.com |
| Networks | eip155:8453 |
| Payment schemes | exact |
| Self-reported calls, 30 days | 0 from 0 payers (the provider's figure, not ours) |
Our checks, last 30 days
We never call tools that send, buy, move money or file anything, not even without paying.
Example input (from the provider)
{
"body": {
"base_operation_id": "base-operation-example-0001",
"buyer_id": "buyer_aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
"confidence": 0.95,
"delegation_fingerprint": "hmac-sha256:dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd",
"event_id": "evt_example_catalog_0001",
"event_value_currency": "EUR",
"event_value_eur": 150,
"method_id": "webhook_integrity.v1",
"payload": {
"delivery_id": "example_delivery_0001",
"event_type": "example.received"
},
"schema_version": "integrityphase.verify_webhook_integrity.request.v3",
"signature": "sha256=0000000000000000000000000000000000000000000000000000000000000000",
"source": {
"source_id": "source_example_catalog_0001",
"type": "webhook"
},
"source_operation_fingerprint": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
"timestamp": "2026-01-01T00:00:00.000Z",
"use_case": "saas_webhook_integrity",
"wallet_address_hash": "sha256:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc"
},
"bodyType": "json",
"method": "POST",
"type": "http"
}
Promised output schema (from the provider)
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false,
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"body": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false,
"properties": {
"base_operation_id": {
"pattern": "^[A-Za-z0-9][A-Za-z0-9._:-]{2,127}$",
"type": "string"
},
"buyer_id": {
"pattern": "^buyer_[a-f0-9]{40}$",
"type": "string"
},
"confidence": {
"maximum": 1,
"minimum": 0.75,
"type": "number"
},
"delegation_fingerprint": {
"pattern": "^hmac-sha256:[a-f0-9]{64}$",
"type": "string"
},
"event_id": {
"pattern": "^[A-Za-z0-9][A-Za-z0-9._:-]{2,127}$",
"type": "string"
},
"event_value_currency": {
"const": "EUR"
},
"event_value_eur": {
"maximum": 200,
"minimum": 100,
"multipleOf": 0.01,
"type": "number"
},
"method_id": {
"const": "webhook_integrity.v1"
},
"payload": {
"type": "object"
},
"schema_version": {
"const": "integrityphase.verify_webhook_integrity.request.v3"
},
"signature": {
"pattern": "^sha256=[a-f0-9]{64}$",
"type": "string"
},
"source": {
"additionalProperties": false,
"properties": {
"source_id": {
"pattern": "^[A-Za-z0-9][A-Za-z0-9._:-]{2,127}$",
"type": "string"
},
"type": {
"enum": [
"webhook",
"api"
],
"type": "string"
}
},
"required": [
"source_id",
"type"
],
"type": "object"
},
"source_operation_fingerprint": {
"pattern": "^sha256:[a-f0-9]{64}$",
"type": "string"
},
"timestamp": {
"format": "date-time",
"pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}\\.[0-9]{3}Z$",
"type": "string"
},
"use_case": {
"maxLength": 100,
"minLength": 3,
"pattern": "^[A-Za-z0-9][A-Za-z0-9._:-]{2,99}$",
"type": "string"
},
"wallet_address_hash": {
"pattern": "^sha256:[a-f0-9]{64}$",
"type": "string"
}
},
"required": [
"schema_version",
"buyer_id",
"wallet_address_hash",
"delegation_fingerprint",
"base_operation_id",
"event_id",
"method_id",
"event_value_eur",
"event_value_currency",
"source_operation_fingerprint",
"source",
"payload",
"timestamp",
"signature"
],
"type": "object",
"x-integrityphase-payload-maximum-nesting-depth": 64,
"x-integrityphase-request-body-max-bytes": 1000000
},
"bodyType": {
"const": "json",
"type": "string"
},
"method": {
"const": "POST",
"type": "string"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method",
"bodyType",
"body"
],
"type": "object"
},
"output": {
"additionalProperties": false,
"properties": {
"example": {
"type": "object"
},
"type": {
"const": "json",
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}