Protect

Webhooks and security

The SDK verifies the signature, timestamp, and nonce against the raw request body before applying a command. Configure the previous secret explicitly during rotation.

x-acp-signature

Hex HMAC-SHA256 digest.

x-acp-timestamp

Unix seconds; rejected beyond 300s drift.

x-acp-nonce

Single use; a repeat is rejected.

Express signature verification

        

Receiver checklist

  • Sign over the exact string timestamp + "." + nonce + "." + body.
  • Reject a missing header, a stale timestamp, or a seen nonce with 403.
  • Accept both ACP_WEBHOOK_SECRET and ACP_WEBHOOK_SECRET_PREV during an overlapping rotation window.
  • Return quickly. The dispatcher retries, so make the handler idempotent by command_id.