Mailhooks icon

Mailhooks

Consume the Mailhooks API

Utility → Verify Webhook

AI-generated

Summary

Verify a Mailhooks webhook signature by comparing the provided signature header with an HMAC-SHA256 hash of the raw webhook payload using the webhook secret.

Inputs

  • Webhook Payload (required) — The raw webhook payload string received from the webhook.
  • Webhook Signature (required) — The signature value taken from the X-Webhook-Signature header to verify.
  • Webhook Secret (required) — The webhook secret key (starting with whsec_) used to generate and verify the signature.

Output shape

a single JSON object indicating whether the signature is valid with a boolean property 'valid'.

The output JSON includes a 'valid' boolean field that is true if the signature matches the calculated HMAC-SHA256 of the payload with the secret, or false otherwise.

Examples

Example 1: Signature is verified successfully

Webhook Payload, Webhook Signature, and Webhook Secret are provided as inputs to verify the signature validity of a webhook request payload.

Links

Discussion