waiaconnect

Documentação / Essencial

Autenticar o webhook: header estático vs assinatura

Markdown

Cada entrega vai SEMPRE assinada e, ALÉM DISSO, pode levar um header estático (um token fixo num header próprio, ex. X-Connect-Token) se você ativá-lo no seu endpoint. Não são modos excludentes: você escolhe como validar.

Header estático — mais cômodo e mais fraco. Sobre HTTPS prova que quem chama conhece o token, mas NÃO verifica que o corpo não foi alterado, nem impede um replay. É a opção para ferramentas sem código (n8n/Make/Zapier), que o validam com a sua autenticação nativa por header.

Assinatura HMAC — verifica a integridade do corpo E o anti-replay (o timestamp vai dentro do HMAC). Exige escrever um pouco de código. É a garantia forte.

Escolher comodidade está bem; escolhê-la sem saber o que se perde, não. Se puder, valide a assinatura; se usa no-code, ative o header estático e valide-o com a sua ferramenta.

# Static header check on the server that RECEIVES the webhook.
# Connect sends your token in the "X-Connect-Token" header on every delivery.
# Compare it in CONSTANT time against the token you stored.
#   if [ "$http_x_connect_token" != "$YOUR_TOKEN" ]; then reject 401; fi
import crypto from "crypto";
const TOKEN = "wct_YOUR_TOKEN"; // the wct_… you stored (from the panel)

function checkHeader(req) {
  const got = req.header("X-Connect-Token") || "";
  const a = Buffer.from(got), b = Buffer.from(TOKEN);
  // constant-time compare (avoid a length/timing leak)
  return a.length === b.length && crypto.timingSafeEqual(a, b);
}
<?php
$TOKEN = "wct_YOUR_TOKEN"; // the wct_… you stored (from the panel)

function checkHeader(array $headers): bool {
  $got = $headers["X-Connect-Token"] ?? "";
  return hash_equals($GLOBALS["TOKEN"], $got); // constant-time compare
}
import hmac

TOKEN = "wct_YOUR_TOKEN"  # the wct_… you stored (from the panel)

def check_header(headers) -> bool:
    got = headers.get("X-Connect-Token", "")
    return hmac.compare_digest(got, TOKEN)  # constant-time compare

O header se chama como você quiser (padrão X-Connect-Token), NUNCA Authorization. Você o gera/gira no seu endpoint (Webhooks) e ele é mostrado UMA única vez.

Compare o token em tempo constante (como abaixo). O exemplo de verificação de assinatura está em 'Verificar a assinatura'.