Webhook Signature Verifier

Verifies HMAC webhook signatures in the Stripe, GitHub, Shopify and generic styles using constant-time comparison, with an optional timestamp tolerance.

POST /v1/developer/webhook-signature-verify $0.005 per call

Specification

Endpoint
POST /v1/developer/webhook-signature-verify
Price
$0.005 per call · tier basic_data
Payment
x402 on X Layer (chain 196) · settled in USDG or USDT0 · schemes exact, aggr_deferred
Data source
Deterministic local computation on caller-supplied input
Timeout
15 seconds
Max request
2 MB
Version
1.0.0

Calling it

The first call returns a 402 with the payment challenge. Retry with a signed authorisation in the X-PAYMENT header — see the payment guide for the exact shape.

curl -i -X POST "https://api.dana-edu.pp.ua/v1/developer/webhook-signature-verify" \
  -H "content-type: application/json" \
  -d '{ ... }'

Response

Real output, captured by running this endpoint at build time — not written by hand. Volatile fields such as timestamps are elided. Captured 2026-07-30.

{
  "valid": false,
  "style": "github",
  "algorithm": "sha256",
  "encoding": "hex",
  "signature_parsed": true,
  "digest_matches": false,
  "timestamp_checked": false,
  "timestamp_within_tolerance": null,
  "note": "Verification failed. The computed digest is not returned, to avoid turning this endpoint into a signing oracle."
}

Every response is wrapped in the same envelope: data plus warnings, sources, confidence, informational_only and a measured processing_ms. See the envelope reference.

Related endpoints