X-Connect-Signature-256: sha256=HMAC_SHA256(secret, "<X-Connect-Timestamp>.<cuerpo crudo>"). Calcola l'HMAC sul timestamp + "." + i byte grezzi della richiesta (ri-serializzare il JSON cambia l'hash) e confrontalo in tempo costante. Il timestamp è DENTRO l'HMAC → un payload intercettato non si può rimandare; rifiuta le consegne più vecchie di 5 minuti. Il secret (whsec_…) viene mostrato UNA volta quando crei l'endpoint.
# Verify X-Connect-Signature-256 on the server that RECEIVES the webhook.
# The header is: sha256=HMAC_SHA256(secret, "<X-Connect-Timestamp>.<raw body>")
# Recompute it over the timestamp + "." + the EXACT raw request body and compare.
# (Shell alone can't compare in constant time — use one of the snippets below.)
echo -n "${TIMESTAMP}.${RAW_BODY}" | openssl dgst -sha256 -hmac "whsec_YOUR_ENDPOINT_SECRET"È il punto dove si blocca più gente e dove molti finiscono per non validare niente (una falla di sicurezza). Questo codice è completo e corretto nei 4 linguaggi.
Il secret reale viene dal tuo endpoint in Webhook (viene mostrato una sola volta; puoi ruotarlo).