---
title: Webhook-endoint
slug: test-archbee/webhook-endoint
docTags: 
createdAt: 2024-12-11T14:13:33.000Z
---

```javascript
// Webhook endpoint
app.post('/webhook', (req, res) => {
  const payload = req.body; // Extract the payload
  const receivedSignature = req.headers['x-signature']; // Extract the signature from headers
  const timestamp = req.headers['x-timestamp']; // Extract the timestamp from headers (if needed)

  if (!receivedSignature || !timestamp) {
    return res.status(400).send('Missing signature or timestamp');
  }

  // Recreate the string to sign
  const payloadString = JSON.stringify(payload);
  const stringToSign = `${timestamp}.${payloadString}`;

  // Recreate the signature
  const calculatedSignature = crypto
    .createHmac('sha256', signingKey)
    .update(stringToSign)
    .digest('hex');

  // Compare the received signature with the calculated signature
  if (receivedSignature === calculatedSignature) {
    console.log('Signature verified! Decoded payload:', payload);

    // Process the payload (e.g., log it, store it, etc.)
    res.status(200).send('Payload received and verified!');
  } else {
    console.error('Signature mismatch. Potential tampering detected!');
    res.status(403).send('Invalid signature');
  }
});
```
