Every request carries LeadFast-Signature: t=UNIX_SECONDS,v1=HEX_HMAC. Read the exact raw body bytes before JSON parsing, then compute:
Compare the hexadecimal digest to v1 in constant time. Reject timestamps outside the five-minute tolerance window. Keep the signing secret on the server: it has no automatic expiration, and regenerating it invalidates the old one immediately and pauses delivery until a new test succeeds.
Never put the signing secret in browser code, logs, commits, or prompts. Read it from an environment variable such as LEADFAST_WEBHOOK_SECRET.
Node.js
Checklist
- Preserve the raw request bytes: parse JSON only after verification.
- Deduplicate by
LeadFast-Delivery, not by payload content.
- Return 2xx quickly, then process asynchronously.
- Add tests for a valid signature, a changed body, an expired timestamp, and a duplicate delivery.