# verify-github-webhook-secret

> Verifies the secret that is sent in GitHub Webhooks

Latest version **3.0.2** (published 2023-07-18) · MIT license · 0 weekly downloads

## Install

```sh
npm install verify-github-webhook-secret
pnpm add verify-github-webhook-secret
yarn add verify-github-webhook-secret
bun add verify-github-webhook-secret
```

## Health

**Score 35/100 (D)** — status: abandoned.

Positive: esm support; no vulnerabilities; high maintenance score.

Warnings: low downloads; no types.

Negative: abandoned.

## Facts

| | |
|---|---|
| Version | 3.0.2 |
| Published | 2023-07-18 |
| First published | 2018-10-31 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | ESM |
| Node | >= 16.0.0 |
| Dependencies | 2 |
| Unpacked size | 7 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 3 |
| Author | Christian Rackerseder |
| Maintainers | screendriver |
| Keywords | secret, github, webhook |

## Links

- npm: https://www.npmjs.com/package/verify-github-webhook-secret
- Repository: https://github.com/screendriver/verify-github-webhook-secret
- Homepage: https://github.com/screendriver/verify-github-webhook-secret#readme
- Issues: https://github.com/screendriver/verify-github-webhook-secret/issues
- npm.io page: https://npm.io/package/verify-github-webhook-secret

## Dependencies (2)

- [micro](https://npm.io/package/micro.md) 10.0.1
- [tslib](https://npm.io/package/tslib.md) 2.6.0

## Recent versions

- 3.0.2 (latest) — 2023-07-18
- 2.0.11 — 2023-07-18
- 3.0.1 — 2023-07-16
- 2.0.10 — 2023-07-13
- 2.0.9 — 2023-01-27
- 2.0.8 — 2022-10-31
- 2.0.7 — 2022-04-22
- 2.0.6 — 2021-08-12
- 2.0.5 — 2021-06-12
- 2.0.4 — 2021-05-07
- 2.0.3 — 2021-01-06
- 2.0.2 — 2020-10-11
- 2.0.1 — 2020-10-07
- 2.0.0 — 2019-08-30
- 1.1.0 — 2019-01-09
- … 5 more at https://npm.io/package/verify-github-webhook-secret/versions

## README

# verify-github-webhook-secret

[![GitHub Actions status](https://github.com/screendriver/verify-github-webhook-secret/workflows/CI/badge.svg)](https://github.com/screendriver/verify-github-webhook-secret/actions)
[![codecov](https://codecov.io/gh/screendriver/verify-github-webhook-secret/branch/main/graph/badge.svg)](https://codecov.io/gh/screendriver/verify-github-webhook-secret)
[![semantic-release](https://img.shields.io/badge/%20%20%F0%9F%93%A6%F0%9F%9A%80-semantic--release-e10079.svg)](https://github.com/semantic-release/semantic-release)

Verifies the [secret](https://developer.github.com/v3/repos/hooks/#create-hook-config-params) that is sent in [GitHub Webhooks](https://developer.github.com/webhooks/). The `secret` will be used as the key to generate the HMAC hex digest value in the `X-Hub-Signature` header.

## Installation 🏗

```sh
$ npm install --save verify-github-webhook-secret
```

or if you use [Yarn](https://yarnpkg.com) 🐈

```sh
$ yarn add verify-github-webhook-secret
```

## Usage 🔨

The exported function needs a [http.IncomingMessage](https://nodejs.org/api/http.html#http_class_http_incomingmessage) and your personal `secret` string. It returns a Promise that fulfills with a boolean if the received secret is valid or not.

You can use it for example with [micro](https://github.com/zeit/micro) as follows:

```ts
import micro from "micro";
import { verifySecret } from "verify-github-webhook-secret";

const server = micro(async (req) => {
	const valid = await verifySecret(req, "my-secret");
	return valid ? "Allowed" : "Not allowed";
});
```

Another way to call the function is directly with the HTTP body and the `x-hub-signature` HTTP header. This is useful in an scenario where you don't have an `IncomingMessage` like in some [serverless](https://en.wikipedia.org/wiki/Serverless_computing) environments.

```ts
import { verifySecret } from "verify-github-webhook-secret";

async function myFunc() {
	const valid = await verifySecret('{"foo":"bar"}', "my-secret", "sha1=30a233839fe2ddd9233c49fd593e8f1aec68f553");
	return valid ? "Allowed" : "Not allowed";
}
```

---
_Source: https://npm.io/package/verify-github-webhook-secret · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
