Day 032 / APIs / Webhook Security

Webhook Signature Lab

View source ↗Scroll to explore ↓
Webhook Signature Lab project cover
/ Overview

A dependency-free Python CLI for signing and verifying local webhook payloads with timestamped HMAC-SHA256, constant-time comparison and replay-age checks.

NameWebhook Signature Lab

ClientIndependent daily build

IndustriesDeveloper and integration tooling

DateDay 032 · October 1, 2026

/ Challenge

A webhook handler must verify the exact raw payload bytes, use the provider's signing scheme and reject stale requests. Small mistakes in byte handling, timestamp checks or string comparison can make a verifier unreliable.

/ Provided services

Clear thinking.
Practical delivery.

01

Local signature generation

Creates a reviewable t=timestamp,v1=signature header from exact payload bytes and a secret read from an environment variable.

02

Defensive verification

Separates signature matching from timestamp freshness so changed payloads, wrong secrets and expired requests remain distinct.

03

Explicit safety boundary

Makes no network request, stores no secret and documents that production integrations must follow each provider's exact specification.

Webhook Signature Lab feature visual
/ Solution

Webhook Signature Lab implements a deliberately small provider-neutral exercise: timestamp plus a period plus exact payload bytes are signed with HMAC-SHA256. It parses a bounded signature header, supports multiple v1 values for key-rotation practice, compares signatures in constant time and checks an explicit timestamp tolerance.

/ Impact

Timestamped HMAC-SHA256 signatures

Exact raw-byte verification

Constant-time comparison

Replay-age tolerance checks

Secrets omitted from every report

Twelve standard-library tests included

/ Tech stack

Python standard library

Hmac, hashlib, argparse, pathlib, regular expressions and JSON provide the complete dependency-free CLI.

Webhook security

Exercises raw-byte signing, bounded header parsing, constant-time comparison and replay-age validation.

Unittest

Twelve tests cover known signatures, round trips, payload changes, wrong secrets, timestamp boundaries, multiple signatures and CLI behavior.

Next project

API Request Builder

View case study ↗