How do I secure my webhook endpoint?
Every webhook delivery is signed with your endpoint's secret, so your endpoint can confirm a message came from Projul and was not altered.
Steps
- Take the raw request bytes, before parsing, and the Projul-Signature header's t value.
- Compute HMAC-SHA256 of "t.raw_body" with your secret, as lowercase hex.
- Compare it to the header's v1 value with a constant-time comparison.
- Reject the delivery if t is more than five minutes from your clock, even if it matches.
What happens
A verified delivery is safe to act on. Answer with a 2xx once you've stored it, then do the work after. Projul retries a failure for about a day before giving up and emailing your account.

Note: If you rotate the secret, the old one still verifies for 24 hours while you switch over.
See How do I get notified when something changes in Projul? and Webhook Event Types: A Complete Breakdown
Questions? Let's Chat.
support@projul.com
(844) 776-5853