Skip to main content
X-Robase-Signature is hex-encoded HMAC-SHA256 of the exact bytes in the body, keyed with the workspace signing secret (dashboard → Webhooks). Re-parsing and re-serializing JSON will not match. The body is compact (no pretty-print) and does not HTML-escape <>& in data.message. Respond 2xx only after the signature checks out. Reject with 401 or 403 and Robase stops rather than retrying, so a rejected delivery never queues behind your traffic.

Node.js

Go

PHP

Official SDKs also expose signature helpers. Rotate the secret in the dashboard if it leaks; verifiers still using the old secret will fail immediately. Rotation takes effect at once, queued deliveries included — each one is signed when it is sent, not when it is queued. Treat data.id as an idempotency key on your side so a retried delivery is not processed twice.