Assinatura HMAC
Cada POST inclui os headers:
| Header | Conteúdo |
|---|---|
Content-Type | application/json |
X-Shatin-Event | o tipo do evento (ex.: transaction.paid) |
X-Shatin-Timestamp | timestamp Unix em segundos usado na assinatura |
X-Shatin-Signature | HMAC-SHA256 em hex |
Cálculo da assinatura:
signature = HMAC_SHA256(signing_secret, `${timestamp}.${rawBody}`) // hexonde rawBody é o corpo JSON exato recebido e timestamp é o valor de X-Shatin-Timestamp.
Exemplo de verificação (Node.js):
const crypto = require('crypto');
function verifyWebhook(rawBody, headers, signingSecret) { const timestamp = headers['x-shatin-timestamp']; const signature = headers['x-shatin-signature']; const expected = crypto .createHmac('sha256', signingSecret) .update(`${timestamp}.${rawBody}`) .digest('hex'); return crypto.timingSafeEqual( Buffer.from(signature), Buffer.from(expected), );}