> ## Documentation Index
> Fetch the complete documentation index at: https://docs.leadfast.vip/llms.txt
> Use this file to discover all available pages before exploring further.

# Verify signatures

> HMAC-SHA256 over raw bytes, with a five-minute tolerance window.

Every request carries `LeadFast-Signature: t=UNIX_SECONDS,v1=HEX_HMAC`. Read the exact raw body bytes before JSON parsing, then compute:

```
HMAC-SHA256(secret, UTF8(timestamp + "." + delivery_id + ".") || raw_body)
```

Compare the hexadecimal digest to `v1` in constant time. Reject timestamps outside the five-minute tolerance window. Keep the signing secret on the server: it has no automatic expiration, and regenerating it invalidates the old one immediately and pauses delivery until a new test succeeds.

<Warning>
  Never put the signing secret in browser code, logs, commits, or prompts. Read it from an environment variable such as `LEADFAST_WEBHOOK_SECRET`.
</Warning>

## Node.js

```js theme={null}
import { createHmac, timingSafeEqual } from 'node:crypto'

export function verifyLeadFast(request, rawBody, secret) {
  const signature = request.headers['leadfast-signature'] ?? ''
  const delivery = request.headers['leadfast-delivery'] ?? ''
  const parts = Object.fromEntries(
    signature.split(',').map((part) => part.split('=')),
  )
  const timestamp = Number(parts.t)
  if (!timestamp || Math.abs(Date.now() / 1000 - timestamp) > 300) return false
  const expected = createHmac('sha256', secret)
    .update(`${parts.t}.${delivery}.`)
    .update(rawBody)
    .digest('hex')
  const received = parts.v1 ?? ''
  return (
    received.length === expected.length &&
    timingSafeEqual(Buffer.from(received, 'hex'), Buffer.from(expected, 'hex'))
  )
}
```

## Checklist

* Preserve the raw request bytes: parse JSON only after verification.
* Deduplicate by `LeadFast-Delivery`, not by payload content.
* Return 2xx quickly, then process asynchronously.
* Add tests for a valid signature, a changed body, an expired timestamp, and a duplicate delivery.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.