Philiprehberger.WebhookSignature
0.2.7
dotnet add package Philiprehberger.WebhookSignature --version 0.2.7
NuGet\Install-Package Philiprehberger.WebhookSignature -Version 0.2.7
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Philiprehberger.WebhookSignature" Version="0.2.7" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Philiprehberger.WebhookSignature" Version="0.2.7" />
<PackageReference Include="Philiprehberger.WebhookSignature" />
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Philiprehberger.WebhookSignature --version 0.2.7
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
#r "nuget: Philiprehberger.WebhookSignature, 0.2.7"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Philiprehberger.WebhookSignature@0.2.7
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Philiprehberger.WebhookSignature&version=0.2.7
#tool nuget:?package=Philiprehberger.WebhookSignature&version=0.2.7
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
Philiprehberger.WebhookSignature
HMAC webhook signing and verification with replay prevention — supports SHA-256, SHA-384, and SHA-512.
Installation
dotnet add package Philiprehberger.WebhookSignature
Usage
using Philiprehberger.WebhookSignature;
// Sign a payload (defaults to HMAC-SHA256)
var signature = Webhook.Sign(payload, "your-secret");
// Verify a signature
bool valid = Webhook.Verify(payload, signature, "your-secret");
// With custom replay tolerance (default: 300 seconds)
bool valid = Webhook.Verify(payload, signature, "your-secret", toleranceSeconds: 60);
Algorithm Selection
Choose between SHA-256, SHA-384, and SHA-512:
// Sign with SHA-512
var signature = Webhook.Sign(payload, "your-secret", algorithm: HashAlgorithm.SHA512);
// Verify with SHA-512
bool valid = Webhook.Verify(payload, signature, "your-secret", algorithm: HashAlgorithm.SHA512);
Header Extraction
Extract signatures from HTTP header dictionaries with case-insensitive matching:
var headers = new Dictionary<string, string>
{
["X-Webhook-Signature"] = signature
};
// Uses "X-Webhook-Signature" by default
string? sig = Webhook.ExtractFromHeaders(headers);
// Or specify a custom header name
string? sig = Webhook.ExtractFromHeaders(headers, "X-Custom-Sig");
Key Rotation
Verify against multiple secrets during key rotation:
var secrets = new[] { "new-secret", "old-secret" };
bool valid = Webhook.VerifyWithKeyRotation(payload, signature, secrets);
// With custom tolerance and algorithm
bool valid = Webhook.VerifyWithKeyRotation(
payload, signature, secrets,
toleranceSeconds: 60,
algorithm: HashAlgorithm.SHA512);
Dependency Injection
var verifier = new WebhookVerifier("your-secret", toleranceSeconds: 300);
bool valid = verifier.Verify(payload, signature);
// With a specific algorithm
var verifier = new WebhookVerifier("your-secret", algorithm: HashAlgorithm.SHA384);
ASP.NET Controller
[HttpPost("webhook")]
public IActionResult HandleWebhook(
[FromBody] string payload,
[FromHeader(Name = "X-Signature")] string signature)
{
if (!Webhook.Verify(payload, signature, _secret))
return Unauthorized();
// Process webhook...
return Ok();
}
API
| Method | Description |
|---|---|
Webhook.Sign(payload, secret, timestamp?, algorithm?) |
Sign a payload, returns {timestamp}.{hex-hmac} |
Webhook.Verify(payload, signature, secret, toleranceSeconds?, algorithm?) |
Verify signature with replay prevention |
Webhook.ExtractFromHeaders(headers, headerName?) |
Extract signature from header dictionary (case-insensitive) |
Webhook.VerifyWithKeyRotation(payload, signature, secrets, toleranceSeconds?, algorithm?) |
Verify against multiple secrets for key rotation |
WebhookVerifier.Verify(payload, signature) |
Instance method for DI scenarios |
Signature Format
Signatures use the format {unix-timestamp}.{hex-encoded-hmac}. The timestamp is included in the HMAC input to prevent replay attacks.
Development
dotnet build src/Philiprehberger.WebhookSignature.csproj --configuration Release
Support
If you find this project useful:
License
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
-
net8.0
- No dependencies.
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.