Signature Algorithm
Kyren Pay uses HMAC-SHA256 to sign webhook payloads:Verification Steps
1
Extract headers
Read
X-Kyren-Signature and X-Kyren-Timestamp from the request headers.2
Check timestamp
Verify the timestamp is within 5 minutes (300000 milliseconds) of the current time. This prevents replay attacks.
3
Compute expected signature
Concatenate
timestamp + "." + raw_request_body, then compute HMAC-SHA256 using your webhook secret.4
Compare signatures
Compare the computed signature with the one in the header. Use constant-time comparison to prevent timing attacks.