When verifying Finix webhook signatures, compute HMAC-SHA256 over the literal string `{timestamp}:{raw body}` using your webhook's secret signing key, and compare against the `sig` value from the comma-separated `Finix-Signature: timestamp=[unix], sig=[hex]` header (look it up case-insensitively, hex-decode before comparing, constant-time compare). Verify against the RAW request bytes: any JSON parse/re-serialize changes whitespace and breaks the HMAC. Treat a missing or malformed `Finix-Signature` header as failed verification, never as trusted. And enforce a replay window: reject deliveries whose timestamp is more than a few minutes old. The signing key itself comes from the `secret_signing_key` returned when you create the webhook via the API.