Tabs cryptographically signs all outbound webhook deliveries using HMAC SHA-256. Every delivery includes a Tabs-Signature HTTP header that lets your server verify the payload’s integrity and authenticity.
The header contains a timestamp and one or more signatures separated by commas:
t: The UNIX timestamp (in seconds) when the signature was computed.
v1: The hexadecimal HMAC-SHA256 hash of the payload signed with your endpoint’s secret (whsec_...).
Verification steps
To verify an incoming webhook:
- Extract timestamp and signature: Parse
t and v1 from the Tabs-Signature header.
- Prevent replay attacks: Compute
Date.now() / 1000 - timestamp. If the difference exceeds your tolerance window (we recommend 300 seconds / 5 minutes), reject the request.
- Construct the signed payload: Concatenate the string timestamp, a period (
.), and the raw untouched request body:
- Compute expected HMAC: Generate an HMAC with SHA-256 using your endpoint secret (
whsec_...) as the key and signedPayload as the data.
- Constant-time comparison: Compare the computed signature to the
v1 value using constant-time string comparison to prevent timing attacks.
Always verify using the raw request body buffer or string. Do not parse JSON before signature verification, as JSON key ordering or whitespace normalization will invalidate the signature.
Code examples