DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk3 min

A Valid Webhook Signature Is Not Authorization

Webhook signature verification authenticates a delivery and protects its integrity; your application must still decide whether the event is authorized to change a resource.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

No. A valid webhook signature can authenticate a delivery and show that its signed payload has not been altered, but it does not decide whether your application should let that event change a particular account, tenant, resource, or record. Verify the signature first; then apply your own authorization rules before performing the requested action.

What webhook signature verification proves

For GitHub webhooks, the X-Hub-Signature-256 header contains an HMAC-SHA256 digest of the request body, calculated with the webhook secret. Recalculate the digest from the exact body bytes your server received, then compare it with the header using a constant-time comparison. GitHub warns against an ordinary == comparison and against allowing a proxy or load balancer to modify the payload before verification. See GitHub’s webhook signature validation guidance.

A successful check means the body matches a message made with the configured secret and has remained intact. It does not prove that the event is fresh, has not been delivered before, or is permitted to trigger a particular effect in your system. The secret must also be stored and handled securely; anyone who obtains it may be able to create a valid signature.

Authentication and authorization answer different questions

Check Question it answers Who defines the decision?
Signature validation Does this payload match one signed with the configured sender secret, and has the signed body remained intact? The provider’s signing scheme and your correct implementation of it.
Authorization May this event perform this operation on this resource for this tenant or account under current policy? Your receiving application.

A correctly signed event may still refer to an unexpected tenant, a resource your service does not control, or an operation that your current policy forbids. Treat the signature as an authentication and integrity check—not as a grant of permission.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Process a delivery in separate security steps

  1. Verify authenticity and integrity. For GitHub, use the configured secret, the original unmodified request body, and X-Hub-Signature-256. Reject a missing or invalid signature before acting on the payload. The older X-Hub-Signature header uses HMAC-SHA1 and is retained for compatibility; do not accept a header merely because it is present. Recompute and compare using the appropriate configured scheme. See GitHub’s event and payload documentation.
  2. Detect duplicates and replays. Use the delivery identifier to recognize deliveries you have already handled, and make side effects safe to retry. GitHub documents X-GitHub-Delivery as unique per event; a redelivery retains the original identifier. A valid signature alone does not establish freshness or uniqueness. See GitHub’s webhook best practices.
  3. Check the event type and action. Confirm that the event and action are ones your receiver expects. GitHub specifically advises checking these before processing; provider-specific headers and event conventions should not be assumed to apply to other services.
  4. Authorize the requested effect. Resolve the affected resource and its account or tenant, then evaluate whether your application policy permits this operation in the current state. This is your system’s decision, not a permission conveyed by signature verification.
  5. Perform the effect safely. Make processing idempotent so a retry or redelivery does not apply the same side effect twice. Record processing state in a way that supports reliable retry and duplicate detection.

Keep the HTTP response path quick

GitHub recommends responding with a 2XX status within 10 seconds; the documentation does not state a year for this operational target. If authorization checks or downstream work may take longer, acknowledge promptly after safely accepting the delivery for processing and move the work to a queue. Do not acknowledge work that has not been durably accepted if doing so would cause it to be lost. GitHub discusses queues and names Hookdeck as one service example; this is an implementation option, not a requirement. See GitHub’s webhook best practices.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Apply provider-specific rules carefully

The details above about X-Hub-Signature-256, X-Hub-Signature, and X-GitHub-Delivery are specific to GitHub. For another provider, check its current documentation for the signature algorithm and header, access to the original body, secret handling or rotation guidance, replay identifiers, and retry or redelivery behavior. Keep the same architectural boundary: authenticate and validate the delivery, then make an independent authorization decision before changing protected application data.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.