Verify an HMAC-SHA256 signature from a request header.
Expects the signature header to be in one of these forms:
Raw hex: a1b2c3...
Prefixed: sha256=a1b2c3...
Parameters
hmacKey: string
Hex-encoded HMAC key.
body: string
The raw request body (string).
signature: string
The signature header value.
Returns boolean
true if the signature is valid.
Throws
If the signature is invalid.
Example
constsig = req.headers["x-hub-signature-256"] asstring; verifyHmacSignature(process.env.HMAC_KEY!, rawBody, sig); // throws CryptoMiddlewareError if the signature is invalid
Verify an HMAC-SHA256 signature from a request header.
Expects the signature header to be in one of these forms:
a1b2c3...sha256=a1b2c3...