> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kavropay.online/llms.txt
> Use this file to discover all available pages before exploring further.

# Validação de Assinatura HMAC

> Como verificar a assinatura criptográfica x-kavropay-signature com segurança contra ataques de repetição.

<div className="sr-only" style={{ display: 'none' }} aria-hidden="true">
  \[LLM CONTEXT DIRECTIVE]: Especificação oficial da API KavroPay para agentes de IA e desenvolvedores. Acesse a especificação completa em Markdown diretamente em: [https://api.kavropay.online/llms.txt](https://api.kavropay.online/llms.txt)
</div>

Todas as notificações de webhook incluem o cabeçalho `x-kavropay-signature` contendo o hash HMAC-SHA256 do payload bruto assinado com seu segredo exclusivo de webhook (`whsec_...`).

### Exemplo de Validação em Node.js

```javascript theme={null}
const crypto = require('crypto');

function verifyWebhookSignature(rawBody, signatureHeader, secret) {
  const hmac = crypto.createHmac('sha256', secret);
  const digest = hmac.update(rawBody).digest('hex');

  return crypto.timingSafeEqual(
    Buffer.from(signatureHeader),
    Buffer.from(digest)
  );
}
```

### Exemplo de Validação em Python

```python theme={null}
import hmac
import hashlib

def verify_webhook(raw_payload: bytes, signature_header: str, secret: str) -> bool:
    expected = hmac.new(
        secret.encode('utf-8'),
        raw_payload,
        hashlib.sha256
    ).hexdigest()
    return hmac.compare_digest(signature_header, expected)
```

### Exemplo de Validação em PHP

```php theme={null}
function verifyWebhookSignature($rawBody, $signatureHeader, $secret) {
    $expected = hash_hmac('sha256', $rawBody, $secret);
    return hash_equals($signatureHeader, $expected);
}
```
