Skip to content

Verify Svix webhooks

Verify that a webhook really came from Svix before acting on it.

Identifier 'svix'
Import import { verifySvix } from 'verihook/svix'
Headers svix-id
svix-timestamp
svix-signature
or webhook-id / webhook-timestamp / webhook-signature
Signature HMAC-SHA256 of <id>.<timestamp>.<raw body>, keyed with the base64 secret, sent as v1,<base64>. Standard Webhooks headers (webhook-*) are accepted too.
Replay window 300 seconds (options.tolerance)
result.eventType the body’s type

The endpoint’s Signing Secret (whsec_...) from the Svix App Portal or dashboard.

Store it in an environment variable (SVIX_WEBHOOK_SECRET below) and never commit it.

import { verifySvix } from 'verihook/svix';
export async function POST(request: Request) {
const result = await verifySvix(request, process.env.SVIX_WEBHOOK_SECRET!);
if (!result.valid) {
console.warn(result.code, result.reason, result.hint);
return new Response('Invalid signature', { status: 401 });
}
console.log(result.eventType, result.event);
return Response.json({ received: true });
}

request can be a Fetch Request or { headers, body, url? } with the raw body. verifyWebhook('svix', request, secret) from verihook does the same. Read why the raw body matters if verification fails behind a body parser.

app/api/webhooks/svix/route.ts
import { createWebhookHandler } from 'verihook/next';
export const POST = createWebhookHandler('svix', process.env.SVIX_WEBHOOK_SECRET!, async (payload, result) => {
// Runs only for a valid signature
console.log(result.eventType, result.event);
});

Each adapter responds 401 to an invalid signature, 413 to a body over maxBodySize (2 MB by default) and 200 to a duplicate when you pass a dedupeStore.

  • Resend and Clerk send Svix signatures. Use their own identifiers ('resend', 'clerk') for clearer logs; the check is the same.
  • During secret rotation Svix sends several signatures separated by spaces. Any one matching is enough.

signWebhook from verihook/testing builds a correctly signed Svix request for your tests:

import { signWebhook } from 'verihook/testing';
import { verifySvix } from 'verihook/svix';
const hook = await signWebhook('svix', {
secret: 'whsec_dGVzdF9zZWNyZXRfa2V5X2Zvcl9zdml4XzEyMw==',
payload: { id: 'evt_test' },
});
const result = await verifySvix(
{ headers: hook.headers, body: hook.body, url: hook.url },
hook.secret,
);
// result.valid === true

From the command line, npx verihook simulate svix --url http://localhost:3000/webhooks/svix sends one to your local server.

See Testing your handlers for supertest and Fetch Request examples.

Failed results carry a code and often a hint with the likely cause. See Troubleshooting for each error code.

Svix’s webhook documentation