Webhooks
Get your webhook signing secret
The secret that signs your webhook deliveries, for verifying X-Valendata-Signature.
GET
Get your webhook signing secret
Each delivery to your
Compute the signature over the raw request body, compare it in constant time, and reject timestamps more than 5 minutes old. The Web to API guide has Python and TypeScript examples.
For 24 hours after you rotate the secret, the header carries two values, new first:
webhook_url carries two headers:
v1=<new>,v1=<old>. Split on commas and accept the delivery when any value matches.
Reading the secret with an API key needs the webhooks:read scope. You can also see it, and rotate it, in Settings → API Keys in the app.Authorizations
API key with the vd_sk_ prefix. Create keys from Settings, API Keys in the dashboard.
Response
Your signing secret.
Your signing secret. Keep it private.
Example:
"X-Valendata-Signature"
Example:
"HMAC-SHA256 over '<timestamp>.<raw body>'"
Set for 24 hours after a rotation: until then deliveries are also signed with the previous secret.
When the secret was last rotated.

