Webhook signature FAQ
No signatures found matching the expected signature for payload
Body was parsed, or the whsec_ is the wrong one. Stripe writeup.
GitHub webhook secret vs GITHUB_TOKEN
X-Hub-Signature-256 uses the webhook Secret field. A PAT will never verify.
Slack invalid_signature
Signing Secret from Basic Information, plus both Slack headers. Not xoxb-.
Shopify HMAC validation failed
HMAC is the raw body only. Topic and triggered-at are not signed.
Clerk / Svix / Resend
Standard Webhooks. whsec_ then base64 bytes. That is not Stripe’s whsec_ math. Path the provider if you take more than one.
Linear missing webhookTimestamp
That field in the signed JSON is the replay clock. doorbell refuses a body without it.
Twilio signature did not match
Pass the public URL Twilio called, not req.url on localhost. doorbell reads the Host header, not Express trust proxy. http is only for localhost. Behind TLS, set publicUrl to the https URL Twilio signed.
Transfer-Encoding / Content-Length
chunked next to a buffered body is refused. If Content-Length is present and does not match the bytes we read, refuse. Cookie and Expect are refused like Origin.