One API, 40 providers
Payments, developer tools, messaging and regional gateways. Each signature scheme is checked against the provider’s docs, and Stripe, GitHub, Svix and Twilio are also tested against their official SDKs.
import { verifyWebhook } from 'verihook';
const result = await verifyWebhook('stripe', request, process.env.STRIPE_WEBHOOK_SECRET!);
if (result.valid) { console.log(result.eventType, result.event); // typed as StripeEvent}One API, 40 providers
Payments, developer tools, messaging and regional gateways. Each signature scheme is checked against the provider’s docs, and Stripe, GitHub, Svix and Twilio are also tested against their official SDKs.
Your framework, one line
Adapters for Next.js, Express, Fastify, Hono, NestJS, Nuxt, SvelteKit, Remix, Astro and AWS Lambda handle the raw body for you.
Tells you what went wrong
Failed checks return an error code and a hint: a parsed body, the wrong kind of secret, a proxy rewriting the URL.
Test without real traffic
verihook/testing signs requests for every provider, and npx verihook simulate sends them to your local server.