x-kavropay-signature contendo o hash HMAC-SHA256 do payload bruto assinado com seu segredo exclusivo de webhook (whsec_...).
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Como verificar a assinatura criptográfica x-kavropay-signature com segurança contra ataques de repetição.
x-kavropay-signature contendo o hash HMAC-SHA256 do payload bruto assinado com seu segredo exclusivo de webhook (whsec_...).
const crypto = require('crypto');
function verifyWebhookSignature(rawBody, signatureHeader, secret) {
const hmac = crypto.createHmac('sha256', secret);
const digest = hmac.update(rawBody).digest('hex');
return crypto.timingSafeEqual(
Buffer.from(signatureHeader),
Buffer.from(digest)
);
}
import hmac
import hashlib
def verify_webhook(raw_payload: bytes, signature_header: str, secret: str) -> bool:
expected = hmac.new(
secret.encode('utf-8'),
raw_payload,
hashlib.sha256
).hexdigest()
return hmac.compare_digest(signature_header, expected)
function verifyWebhookSignature($rawBody, $signatureHeader, $secret) {
$expected = hash_hmac('sha256', $rawBody, $secret);
return hash_equals($signatureHeader, $expected);
}
