Multi-Webhook Fanout & HMAC Verification
Fan out every submission to up to 5 concurrent webhook endpoints with cryptographic X-EntryWise-Signature verification and SSRF protection.
Verifying X-EntryWise-Signature#
Every webhook dispatched by EntryWise includes an X-EntryWise-Signature header containing the hex-encoded HMAC-SHA256 digest of the raw JSON request body signed with your form’s Webhook Secret.
Node.js / Bun / Cloudflare Worker Verification· verifyWebhook.ts
import crypto from 'node:crypto';
export function verifyEntryWiseWebhook(
rawBody: string,
signatureHeader: string | null,
webhookSecret: string
): boolean {
if (!signatureHeader || !signatureHeader.startsWith('sha256=')) {
return false;
}
const expected =
'sha256=' +
crypto.createHmac('sha256', webhookSecret).update(rawBody).digest('hex');
return crypto.timingSafeEqual(
Buffer.from(signatureHeader),
Buffer.from(expected)
);
}