Skip to main content
Every request carries LeadFast-Signature: t=UNIX_SECONDS,v1=HEX_HMAC. Read the exact raw body bytes before JSON parsing, then compute:
Compare the hexadecimal digest to v1 in constant time. Reject timestamps outside the five-minute tolerance window. Keep the signing secret on the server: it has no automatic expiration, and regenerating it invalidates the old one immediately and pauses delivery until a new test succeeds.
Never put the signing secret in browser code, logs, commits, or prompts. Read it from an environment variable such as LEADFAST_WEBHOOK_SECRET.

Node.js

Checklist

  • Preserve the raw request bytes: parse JSON only after verification.
  • Deduplicate by LeadFast-Delivery, not by payload content.
  • Return 2xx quickly, then process asynchronously.
  • Add tests for a valid signature, a changed body, an expired timestamp, and a duplicate delivery.