Webhook Algorithm (HMAC-SHA512)

Webhooks allow LedgerBlock to notify your application when an event occurs, such as a successful collection or a completed payout. Instead of repeatedly checking the API for updates, your application receives the event directly from LedgerBlock through an HTTP request to your configured webhook URL.

Webhook Algorithm
LedgerBlock signs webhook requests so your application can verify that the notification was sent by LedgerBlock and that the payload has not been modified in transit.

When LedgerBlock sends a webhook:
LedgerBlock generates a signature from the webhook payload using the configured webhook signing algorithm.
The generated signature is included in the request header as x-ledgerblock-signature.
Your application receives the webhook request.
Your application uses the shared webhook secret and the same signing algorithm to generate its own signature from the received payload.
The generated signature is compared with the x-ledgerblock-signature received in the request.
If both signatures match, the webhook can be trusted and processed. If they do not match, the request should be rejected.


Did this page help you?