Multi-Webhook Fanout & HMAC Verification
Docs/Connectors & Email·4 min read

Multi-Webhook Fanout & HMAC Verification

Fan out every submission to up to 5 concurrent webhook endpoints with cryptographic X-EntryWise-Signature verification and SSRF protection.

Verifying X-EntryWise-Signature#

Every webhook dispatched by EntryWise includes an X-EntryWise-Signature header containing the hex-encoded HMAC-SHA256 digest of the raw JSON request body signed with your form’s Webhook Secret.

Node.js / Bun / Cloudflare Worker Verification· verifyWebhook.ts
import crypto from 'node:crypto';

export function verifyEntryWiseWebhook(
  rawBody: string,
  signatureHeader: string | null,
  webhookSecret: string
): boolean {
  if (!signatureHeader || !signatureHeader.startsWith('sha256=')) {
    return false;
  }
  const expected =
    'sha256=' +
    crypto.createHmac('sha256', webhookSecret).update(rawBody).digest('hex');

  return crypto.timingSafeEqual(
    Buffer.from(signatureHeader),
    Buffer.from(expected)
  );
}