WebhooksVerify signature
Verify signature
HMAC-SHA256 of the raw body with the signing_secret.
| Header | Meaning |
|---|---|
| X-Aivyro-Signature | sha256= + hex HMAC-SHA256 of the raw body |
| X-Aivyro-Timestamp | ISO timestamp in the envelope |
| X-Aivyro-Nonce | Unique per delivery |
| X-Aivyro-Public-Event | Public name (contact.created) |
Use event.public_type (or X-Aivyro-Public-Event) as the public name. event.type is internal. Rotate with POST /api/v1/webhooks/{id}/rotate_secret. The new secret is shown once. Old signatures fail.