Skip to content

Webhooks: Securing Your Webhooks

The option of securing your Caspeco webhooks is available by creating a signature on the webhook page in Caspeco Cloud. The signature allows you to verify that the webhook messages received by your receiving endpoint actually come from Caspeco.

To create your signature, head to Settings > Webhooks > Create signature and click the Generate button. Once the signature has been created, you can copy it and use it to secure your webhooks from potential attacks by the verification steps described below.

The Caspeco-Webhooks-Signature header contains a Unix timestamp prefixed by t= and the signature itself prefixed by s=. The signatures are generated using a hash-based message authentication code (HMAC) with a SHA-256 hash.

Split the header using “,” as a separator to get a list of elements. Then divide the elements using the “=” character to get value and prefix pairs.

Once the values have been separated, you can generate your signed_payload string by concatenating the timestamp + “.” + the payload JSON-body.

Create an HMAC with the SHA-256 hash algorithm function. Use the signing secret as key and the generated signed_payload as message.

ComputeSignature(stringToSign, key)
{
using (var hmacsha256 = new HMACSHA256(Convert.FromBase64String(key)))
{
var bytes = Encoding.UTF8.GetBytes(stringToSign);
var hashedBytes = hmacsha256.ComputeHash(bytes);
return Convert.ToBase64String(hashedBytes);
}
}

Compare the signature in the header to your expected signature. If you wish to perform an equality match to protect yourself from replay-like attacks, compute the difference between the current and received timestamps to decide if the difference is within your tolerance range.