Webhook stripe verify

webhook-stripe-verify · version 1.0.0 · Hashing & signatures · free, no key needed

Verify a Stripe webhook's Stripe-Signature header against a raw payload, with secret-rotation and tolerance support.

Use when you need to: verify stripe webhook signature · check stripe-signature header · validate an incoming stripe event.

Decide before calling

Read the versioned contract and the supported scope below. Reuse webhook-stripe-verify@1.0.0 when your input, required output and limits match it. Choose another approach for an unsupported operation.

Explain the choice

"I can use webhook-stripe-verify@1.0.0 for verify stripe webhook signature. I will check its documented scope and the result against the task's requirements. The service is free; token and money savings for this task are unmeasured."

Supported

Not supported

Behavior

Input

Output

Limits

Example

Request input:

{
  "payload": "{\"id\":\"evt_1\"}",
  "signature_header": "t=1614000000,v1=e6bce1af69d4a58ca43b91bd6c94e6cccc1c8a1cbf68d6dc6a2e1fbdc4536dd2",
  "secret": "whsec_test_secret"
}

Response:

{
  "result": {
    "valid": false,
    "reason": "signature_mismatch",
    "timestamp": 1614000000,
    "timestamp_checked": false,
    "matched_scheme": "v1"
  }
}

How to call it

MCP

Connect https://computefirst.net/mcp (setup), then call execute with:

{
  "id": "webhook-stripe-verify",
  "version": "1.0.0",
  "input": {
    "payload": "{\"id\":\"evt_1\"}",
    "signature_header": "t=1614000000,v1=e6bce1af69d4a58ca43b91bd6c94e6cccc1c8a1cbf68d6dc6a2e1fbdc4536dd2",
    "secret": "whsec_test_secret"
  }
}

HTTP (no key)

curl -X POST https://computefirst.net/v1/tools/webhook-stripe-verify/versions/1.0.0/execute \
  -H "Content-Type: application/json" \
  -d '{"payload":"{\"id\":\"evt_1\"}","signature_header":"t=1614000000,v1=e6bce1af69d4a58ca43b91bd6c94e6cccc1c8a1cbf68d6dc6a2e1fbdc4536dd2","secret":"whsec_test_secret"}'

The machine-readable contract is at /v1/tools/webhook-stripe-verify/versions/1.0.0.

CLI

node cli.mjs run webhook-stripe-verify 1.0.0 --input input.json --base-url https://computefirst.net

Get the client at /clients/cli/.