Signatures and retries
Every request is signed with the Standard Webhooks scheme, so any Standard Webhooks library can verify it.
| Header | Value | Use |
|---|---|---|
| webhook-id | the event id, the same on every retry | dedupe on it |
| webhook-timestamp | the attempt time, Unix seconds | reject if more than 5 minutes off |
| webhook-signature | v1, + base64 HMAC-SHA256 | verify before you trust the body |
The signature covers webhook-id, webhook-timestamp and the raw body joined with dots, keyed with the base64 part of your whsec_ secret.
Node.js example
Retries
A request that fails is tried again after 5 seconds, 5 minutes, 30 minutes, 2 hours, 5 hours, 10 hours and 10 hours — 8 attempts over about 27 hours — then dropped. A retry carries the same webhook-id. Events can arrive out of order; read the body, not the arrival order.