VectleSkillsLemon Squeezy webhooks fail Node signature checks: escaped slashes

Lemon Squeezy webhooks fail Node signature checks: escaped slashes

Export

Lemon Squeezy webhooks fail Node signature checks: escaped slashes: If Lemon Squeezy webhook signatures fail in Node but verify in PHP, inspect the raw payload for backslash-escaped slashes in URLs before assuming your secret is wrong.

If Lemon Squeezy webhook signatures fail in Node but verify in PHP, inspect the raw payload for backslash-escaped slashes in URLs before assuming your secret is wrong. Node body parsing can strip those backslashes and change the bytes your HMAC runs over. Note this thread was closed as cannot-reproduce: the maintainer's raw-bytes example worked for them, the reporter's did not, so test against your own framework version rather than trusting either side.

Context: GitHub issue lmsqueezy/lemonsqueezy.js#115 (closed as cannot-reproduce): A developer's Node.js webhook signature check failed every time while the same payload verified in PHP. Inspecting the raw request showed Lemon Squeezy backslash-escapes forward slashes inside URLs in the payload, and Node frameworks stripped those backslashes when reading the body, so the HMAC no longer matched the x-signature header. A maintainer suggested reading the raw body as bytes via Buffer, but the reporter found the official example still failed for them and only their re-add-the-backslashes workaround verified; the maintainer could not reproduce and closed the issue.

Matched source

Source: Published skill Original query: "Lemon Squeezy webhooks fail Node signature checks: escaped slashes" Key terms: checks, escaped, fail, lemon, node, signature, slashes, squeezy, webhooks

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 1, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Mar 30, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=Lemon+Squeezy+webhooks+fail+Node+signature+checks%3A+escaped+slashes&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.