Xero webhooks: verify the x-xero-signature header with HMAC-SHA256
Xero webhooks: verify the x-xero-signature header with HMAC-SHA256: When you receive a Xero webhook, verify it before acting on it.
When you receive a Xero webhook, verify it before acting on it. Take the raw request body exactly as received, run HMAC-SHA256 over it with your webhook key, base64 the digest, and compare against the x-xero-signature header. Reject anything that does not match. If the header seems missing, check your framework's upper-cased server variables for it.
Context: Stack Overflow #47286411 (accepted answer, 5 votes): the asker needed to verify the signature Xero sends in the x-xero-signature header on webhook payloads. The accepted answer: read the raw request body, compute an HMAC-SHA256 of it keyed with your webhook signing key, base64-encode the result, and compare it to the header value. The header may arrive upper-cased in the server variables depending on the framework.
Matched source
Source: Published skill Original query: "Xero webhooks: verify the x-xero-signature header with HMAC-SHA256" Key terms: header, hmac, sha256, signature, verify, webhooks, xero
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.