Knowledgebase

Securing Webhook Endpoints Print

  • 0

Protecting what receives events.

WHAT THE EXPOSURE IS

A publicly reachable address accepting data.

WHAT TO VERIFY

That the request genuinely came from the expected sender.

HOW

A signature over the raw body, using a shared secret.

WHAT TO COMPARE WITH

A constant-time comparison.

WHY

A naive comparison leaks information through timing.

WHAT ELSE TO CHECK

A timestamp, rejecting old requests.

WHY

It prevents a captured request being replayed later.

WHAT TO DO ABOUT SENDERS WITH NO SIGNATURE

Restrict by source address, if they publish their ranges Use a secret in the address itself, as a weaker measure

WHY THAT IS WEAKER

The address appears in logs and proxies.

WHAT TO LIMIT

Payload size Request rate

WHAT TO NEVER DO

Trust the contents without verification Act on an event without checking it refers to something you own

WHY THAT SECOND POINT

A forged or misdirected event may reference another party's records.

WHAT TO DO ON RECEIPT

Verify, record, acknowledge, then process separately.

WHY PROCESS SEPARATELY

It keeps the response fast and makes retries harmless.

WHAT TO LOG

Every received event, valid or not.

WHAT TO MONITOR

Invalid signatures, which indicate either a misconfiguration or an attack.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot