Skip to main content
Signers hash the exact body bytes, not a pretty-printed copy. The event body text can differ from those bytes once it is decoded or truncated. Download the raw body and hash that. The signature the sender attached is on the event headers. Compare your HMAC to that header using the scheme the sender documents (hex, base64, or a t=...,v1=... value).

CLI

Wait for the event, then download its raw body. --file is required.
sha256 on the event is the SHA-256 of those same raw bytes. It is not the HMAC.

TypeScript

event.raw() downloads the raw body. event.headers is the header map as received, so you can read the signature header next to the MAC.

Next steps

Assert in a test

Wait for the request before you check the signature.

Webhook Testing API

Event fields, including headers and the raw download.