const crypto = require('crypto');
function verifyWebhook(rawBody, signatureHeader, secret) {
if (!signatureHeader || !signatureHeader.startsWith('sha256=')) {
return false;
}
const receivedSig = signatureHeader.replace('sha256=', '');
const expectedSig = crypto
.createHmac('sha256', secret)
.update(rawBody)
.digest('hex');
try {
return crypto.timingSafeEqual(
Buffer.from(receivedSig, 'hex'),
Buffer.from(expectedSig, 'hex')
);
} catch (error) {
return false;
}
}
// Usage in your webhook handler (with express.raw middleware)
const rawBody = req.body;
const signature = req.headers['x-vlmrun-signature'];
const secret = process.env.VLMRUN_WEBHOOK_SECRET;
if (!verifyWebhook(rawBody, signature, secret)) {
return res.status(401).json({ error: 'Invalid signature' });
}