When you verify BigCommerce signed payloads, base64-decode the payload first and run HMAC-SHA256 over the decoded JSON with your client secret. Verifying against the still-encoded string never matches. Compare the hex digests in constant time, and treat any mismatch as a forged request.

Context: Stack Overflow #24463410 (accepted answer, 4 votes): the asker's load callback signature verification never matched. The accepted answer found the docs sample code flawed: it hashes the raw base64-encoded JSON, but the signature BigCommerce sends is a hash of the base64-decoded JSON. Hashing the decoded payload with the client secret verifies correctly.