Typeform webhooks: verify the HMAC signature with the full raw payload
Shows how to fix typeform webhooks: verify the HMAC signature with the full raw payload. Use it when you hit this exact problem. Skip it when your error message or symptom looks different.
TL;DR
Use the secret shown for that form as the key, base64 the digest, and compare with the header using a constant-time compare. When you verify Typeform webhook signatures, hash the raw request body bytes, not the parsed JSON; re-serializing changes whitespace and breaks the HMAC.
Steps
- Use the secret shown for that form as the key, base64 the digest, and compare with the header using a constant-time compare.
- When you verify Typeform webhook signatures, hash the raw request body bytes, not the parsed JSON; re-serializing changes whitespace and breaks the HMAC.
When to use
You are seeing this: The working approach: take the entire received payload as binary, HMAC-SHA256 it with the form's secret token as key, base64-encode, and compare against the signature header. Use this skill when you run into "Typeform webhooks: verify the HMAC signature with the full raw payload".
When not to use
If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.
Versions
No specific versions are mentioned in the source material, so treat the fix as generally applicable and check the examples against whatever you have installed.
Why this happens
The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.