How it works
- Starbridge constructs a message by concatenating the webhook ID, timestamp, and body with dots:
- This message is signed with Starbridge’s private key using Ed25519.
- The signature is base64-encoded and sent in the
webhook-signatureheader with av1a,prefix.
Verification steps
To verify a webhook:- Extract the headers — read
webhook-id,webhook-timestamp, andwebhook-signaturefrom the request. - Read the raw body — use the raw request body. Do not parse and re-serialize the JSON, as even minor formatting changes will break verification.
- Reconstruct the signed message:
- Strip the
v1a,prefix from thewebhook-signatureheader and base64-decode the remainder to get the signature bytes. - Strip the
whpk_prefix from your public key and base64-decode the remainder to get the key bytes. - Verify the Ed25519 signature using your language’s crypto library.
Timestamp validation
To protect against replay attacks, check that thewebhook-timestamp is recent (within 5 minutes of the current time). Reject requests with timestamps that are too old.
Idempotency
Use thewebhook-id header as an idempotency key. Store recently processed webhook IDs and skip any duplicates to avoid processing the same event twice.
Code examples
All examples use the following test data:- Python
- JavaScript
- Java
- Go
- Ruby
- C# / .NET