Skip to content
Ask a question in your own words

Verify a webhook came from Mando

Every developer webhook is signed. Verify each delivery by recomputing its signature with your signing secret and rejecting anything older than five minutes.

Written by: Malaz Madani43 minutes ago1 min read

Because your endpoint is a public URL, you should confirm each webhook really came from Mando before acting on it. Every developer webhook is signed for exactly this.

What each delivery carries

Each delivery includes three headers: an id, a timestamp, and a signature. The signature is an HMAC computed over the id, the timestamp, and the raw body, using your endpoint's signing secret.

How to verify

Get your signing secret from the webhook portal, then on each delivery recompute the signature over the raw body and compare it to the header. Reject a delivery whose timestamp is more than about five minutes from now, to block replays.

The portal shows your secret and ready-made verification code, so use its official webhook library rather than writing the check by hand.

Frequently asked questions

Where is my signing secret?

In the webhook portal, on the endpoint. Reveal and copy it there.

Do I compute over the parsed JSON?

No. Verify over the raw request body exactly as received, before parsing.

Are Slack notifications signed?

No. Only the developer webhook stream is signed. Slack posts use your own Slack workspace.

Related articles

Did this answer your question?

More Support

Get more support from us