Overview
3 min
HMAC verification for events
Klavi defaults to using the secretkey and SHA-256 HMAC algorithm to sign the payload.
The following parameter will be included in the request header that Klavi POST to you.
X-Klavi-Signature: 11fad26ccd04a59085a738b8e20be5f4e01887a3c5cdc88cd37bf431e843083e
X-Klavi-Timestamp: 1740716924We recommend that you verify the signature of the webhook. Tips for Best Practice:
Create a SHA-256 HMAC of the request body using your secretKey as the key
Compare it to the signature included on the X-Klavi-Signature header. If the two are equal then the request is valid, otherwise, it is spoofed.
The X-Klavi-Signature and X-Klavi-Timestamp header gets added to every event and product reports.
Here is an example of signature verification in Node.js:
const crypto = require('crypto');
const partnerSecret = '{{SECRET-KEY}}';
router.use('/webhook-handler', (request, res) => {
const body = request.body;
const signature = crypto
.createHmac('sha256', partnerSecret)
.update(JSON.stringify(body))
.digest('hex');
if (request.get('X-Klavi-Signature') !== signature) {
throw new Error('Spoofing detected, rejecting webhook');
}
});