Signature Validation
For security, all webhooks from Chipi Pay include an HMAC signature in thechipi-signature header. You should verify this signature to ensure the webhook is from Chipi Pay and hasn’t been tampered with.
Why Verify Signatures?
Webhook signature verification:- Prevents spoofing - Ensures requests are from Chipi Pay
- Protects data integrity - Detects if payloads have been modified
- Security best practice - Industry standard for webhook security
Getting Your Webhook Secret
- Go to your webhook configuration page in the Chipi Dashboard
- Copy your Webhook Signing Secret (it looks like
whsec_****) - Store it securely as an environment variable
Implementation
Step 1: Install Required Dependencies
Step 2: Create a Signature Verification Function
Step 3: Verify in Your Webhook Handler
Security Best Practices
Common Issues
Signature Mismatch
If you’re getting signature mismatches:- Ensure you’re using the correct webhook secret from your dashboard
- Verify you’re reading the raw request body (not parsed JSON)
- Check that the
chipi-signatureheader is being read correctly - Make sure you’re using SHA-256 HMAC
Environment Variables
Store your webhook secret securely:Next Steps
- Learn more about webhook events
- Set up your webhook configuration
- Explore React SDK hooks
