Skip to content
English
  • There are no suggestions because the search field is empty.

How do I secure my webhook endpoint?

Every webhook delivery is signed with your endpoint's secret, so your endpoint can confirm a message came from Projul and was not altered.

Steps

  1. Take the raw request bytes, before parsing, and the Projul-Signature header's t value.
  2. Compute HMAC-SHA256 of "t.raw_body" with your secret, as lowercase hex.
  3. Compare it to the header's v1 value with a constant-time comparison.
  4. Reject the delivery if t is more than five minutes from your clock, even if it matches.

What happens

A verified delivery is safe to act on. Answer with a 2xx once you've stored it, then do the work after. Projul retries a failure for about a day before giving up and emailing your account.

Note: If you rotate the secret, the old one still verifies for 24 hours while you switch over.

See How do I get notified when something changes in Projul? and Webhook Event Types: A Complete Breakdown

Questions? Let's Chat.
support@projul.com
(844) 776-5853