Philiprehberger.WebhookSignature 0.2.7

dotnet add package Philiprehberger.WebhookSignature --version 0.2.7
                    
NuGet\Install-Package Philiprehberger.WebhookSignature -Version 0.2.7
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Philiprehberger.WebhookSignature" Version="0.2.7" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Philiprehberger.WebhookSignature" Version="0.2.7" />
                    
Directory.Packages.props
<PackageReference Include="Philiprehberger.WebhookSignature" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Philiprehberger.WebhookSignature --version 0.2.7
                    
#r "nuget: Philiprehberger.WebhookSignature, 0.2.7"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Philiprehberger.WebhookSignature@0.2.7
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Philiprehberger.WebhookSignature&version=0.2.7
                    
Install as a Cake Addin
#tool nuget:?package=Philiprehberger.WebhookSignature&version=0.2.7
                    
Install as a Cake Tool

Philiprehberger.WebhookSignature

CI NuGet Last updated

HMAC webhook signing and verification with replay prevention — supports SHA-256, SHA-384, and SHA-512.

Installation

dotnet add package Philiprehberger.WebhookSignature

Usage

using Philiprehberger.WebhookSignature;

// Sign a payload (defaults to HMAC-SHA256)
var signature = Webhook.Sign(payload, "your-secret");

// Verify a signature
bool valid = Webhook.Verify(payload, signature, "your-secret");

// With custom replay tolerance (default: 300 seconds)
bool valid = Webhook.Verify(payload, signature, "your-secret", toleranceSeconds: 60);

Algorithm Selection

Choose between SHA-256, SHA-384, and SHA-512:

// Sign with SHA-512
var signature = Webhook.Sign(payload, "your-secret", algorithm: HashAlgorithm.SHA512);

// Verify with SHA-512
bool valid = Webhook.Verify(payload, signature, "your-secret", algorithm: HashAlgorithm.SHA512);

Header Extraction

Extract signatures from HTTP header dictionaries with case-insensitive matching:

var headers = new Dictionary<string, string>
{
    ["X-Webhook-Signature"] = signature
};

// Uses "X-Webhook-Signature" by default
string? sig = Webhook.ExtractFromHeaders(headers);

// Or specify a custom header name
string? sig = Webhook.ExtractFromHeaders(headers, "X-Custom-Sig");

Key Rotation

Verify against multiple secrets during key rotation:

var secrets = new[] { "new-secret", "old-secret" };
bool valid = Webhook.VerifyWithKeyRotation(payload, signature, secrets);

// With custom tolerance and algorithm
bool valid = Webhook.VerifyWithKeyRotation(
    payload, signature, secrets,
    toleranceSeconds: 60,
    algorithm: HashAlgorithm.SHA512);

Dependency Injection

var verifier = new WebhookVerifier("your-secret", toleranceSeconds: 300);
bool valid = verifier.Verify(payload, signature);

// With a specific algorithm
var verifier = new WebhookVerifier("your-secret", algorithm: HashAlgorithm.SHA384);

ASP.NET Controller

[HttpPost("webhook")]
public IActionResult HandleWebhook(
    [FromBody] string payload,
    [FromHeader(Name = "X-Signature")] string signature)
{
    if (!Webhook.Verify(payload, signature, _secret))
        return Unauthorized();

    // Process webhook...
    return Ok();
}

API

Method Description
Webhook.Sign(payload, secret, timestamp?, algorithm?) Sign a payload, returns {timestamp}.{hex-hmac}
Webhook.Verify(payload, signature, secret, toleranceSeconds?, algorithm?) Verify signature with replay prevention
Webhook.ExtractFromHeaders(headers, headerName?) Extract signature from header dictionary (case-insensitive)
Webhook.VerifyWithKeyRotation(payload, signature, secrets, toleranceSeconds?, algorithm?) Verify against multiple secrets for key rotation
WebhookVerifier.Verify(payload, signature) Instance method for DI scenarios

Signature Format

Signatures use the format {unix-timestamp}.{hex-encoded-hmac}. The timestamp is included in the HMAC input to prevent replay attacks.

Development

dotnet build src/Philiprehberger.WebhookSignature.csproj --configuration Release

Support

If you find this project useful:

Star the repo

🐛 Report issues

💡 Suggest features

❤️ Sponsor development

🌐 All Open Source Projects

💻 GitHub Profile

🔗 LinkedIn Profile

License

MIT

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net8.0

    • No dependencies.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.2.7 122 4/1/2026
0.2.6 116 3/25/2026
0.2.5 106 3/23/2026
0.2.4 102 3/21/2026
0.2.3 119 3/16/2026
0.2.2 109 3/16/2026
0.2.1 115 3/16/2026
0.2.0 115 3/13/2026
0.1.1 126 3/11/2026
0.1.0 117 3/11/2026