Getting started
Install
Section titled “Install”npm install verihookpnpm add verihookyarn add verihookbun add verihookdeno add jsr:@verihook/verihook# or from npmdeno add npm:verihookverihook has no runtime dependencies. It uses the Web Crypto API, with a Node.js fallback, so it runs on Node.js 18.17+, Deno, Bun, Cloudflare Workers and Vercel Edge.
Verify a webhook
Section titled “Verify a webhook”Pass the provider, the incoming request and your webhook secret:
import { verifyWebhook } from 'verihook';
export async function POST(request: Request) { const result = await verifyWebhook('github', request, process.env.GITHUB_WEBHOOK_SECRET!);
if (!result.valid) { // result.code says what failed; result.hint often says why return new Response('Invalid signature', { status: 401 }); }
console.log(result.eventType); // "push", "issues", ... return Response.json({ received: true });}request can be:
- a Fetch
Request(Next.js route handlers, Hono, Cloudflare Workers, Deno, Bun); - an object
{ headers, body, url? }, wherebodyis the raw body as a string or bytes.
Signatures are computed over the exact bytes the provider sent. If a body parser has already turned the body into an object, verification fails. Why the raw body matters explains how to keep it in each framework.
Use your framework’s adapter
Section titled “Use your framework’s adapter”The adapters read the raw body, verify it and answer failed requests for you:
import { createWebhookHandler } from 'verihook/next';
export const POST = createWebhookHandler('stripe', process.env.STRIPE_WEBHOOK_SECRET!, async (payload, result) => { // Runs only when the signature is valid});See the Frameworks section for Express, Fastify, Hono, NestJS, Nuxt, SvelteKit, Remix, Astro and AWS Lambda.
Next steps
Section titled “Next steps”- Find your provider’s page in Providers. It covers where the secret is, which headers are sent and copy-paste code for each framework.
- Test your handlers with signed requests.
- Reject duplicate deliveries with a dedupe store.