# webhook-sign

> Simple HMAC-sha256 based webhook signature creation & validation.

Latest version **1.0.2** (published 2021-03-12) · MIT license · 0 weekly downloads

## Install

```sh
npm install webhook-sign
pnpm add webhook-sign
yarn add webhook-sign
bun add webhook-sign
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.0.2 |
| Published | 2021-03-12 |
| First published | 2021-03-08 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 0 |
| Unpacked size | 4.1 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Author | Bernhard Zens |
| Maintainers | bzens |
| Keywords | webhook, hmac, signature |

## Links

- npm: https://www.npmjs.com/package/webhook-sign
- Repository: https://github.com/gnarrrl/webhook-sign
- Homepage: https://github.com/gnarrrl/webhook-sign#readme
- Issues: https://github.com/gnarrrl/webhook-sign/issues
- npm.io page: https://npm.io/package/webhook-sign

## Recent versions

- 1.0.2 (latest) — 2021-03-12
- 1.0.1 — 2021-03-08
- 1.0.0 — 2021-03-08

## README

# Webhook Signature

### Sign payload of HTTP post with shared secret
```
const whsign = require('webhook-sign');
const axios = require('axios').default;

const payload = { my: 'data' };
const secret = 'my shared secret key string';
const path = 'your target url';

axios.post(path, payload, {
    headers: {
        signature: whsign.sign(payload, secret)
    }
});
```

### Verify payload of HTTP post with shared secret
```
const whsign = require('webhook-sign');

async function main(event) {
    const signature = event.headers.signature;
    const secret = 'my shared secret key string';

    let payload;
    try {
        payload = JSON.parse(event.body);
    } catch (err) {
        // handle error
    }

    // authorize the request
    if (!whsign.verify(signature, secret, payload)) {
        console.log('Signature mismatch or timeout', signature, payload);
        return {
            statusCode: 401
        };
    }
}
```

### Other properties
```
// Change max deviation in seconds between sign and verify (default = 5 seconds)
whsign.setMaxDeviation(2);
```

---
_Source: https://npm.io/package/webhook-sign · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
