Webhook Security
Every webhook request includes a signature so you can verify it originated from Stable Genius and wasn’t tampered with in transit.Signature Header
Each webhook includes aX-StableGenius-Signature header containing an HMAC-SHA256 signature:
Verification Steps
1
Extract headers
Read the
X-StableGenius-Signature and X-StableGenius-Timestamp headers from the request.2
Prepare the signed payload
Concatenate the timestamp and the raw request body with a period:
{timestamp}.{body}3
Compute the expected signature
HMAC-SHA256 the signed payload using your webhook signing secret (found in the dashboard under Settings → Webhooks).
4
Compare signatures
Compare your computed signature with the one in the header. Use a constant-time comparison to prevent timing attacks.
5
Check timestamp freshness
Reject events with timestamps older than 5 minutes to prevent replay attacks.

