Webhook signature FAQ

No signatures found matching the expected signature for payload

Body was parsed, or the whsec_ is the wrong one. Stripe writeup.

GitHub webhook secret vs GITHUB_TOKEN

X-Hub-Signature-256 uses the webhook Secret field. A PAT will never verify.

Slack invalid_signature

Signing Secret from Basic Information, plus both Slack headers. Not xoxb-.

Shopify HMAC validation failed

HMAC is the raw body only. Topic and triggered-at are not signed.

Clerk / Svix / Resend

Standard Webhooks. whsec_ then base64 bytes. That is not Stripe’s whsec_ math. Path the provider if you take more than one.

Linear missing webhookTimestamp

That field in the signed JSON is the replay clock. doorbell refuses a body without it.

Twilio signature did not match

Pass the public URL Twilio called, not req.url on localhost. doorbell reads the Host header, not Express trust proxy. http is only for localhost. Behind TLS, set publicUrl to the https URL Twilio signed.

Transfer-Encoding / Content-Length

chunked next to a buffered body is refused. If Content-Length is present and does not match the bytes we read, refuse. Cookie and Expect are refused like Origin.

Markdown FAQ · GitHub