Skip to main content
GET
Get your webhook signing secret
Each delivery to your webhook_url carries two headers:
Compute the signature over the raw request body, compare it in constant time, and reject timestamps more than 5 minutes old. The Web to API guide has Python and TypeScript examples. For 24 hours after you rotate the secret, the header carries two values, new first: v1=<new>,v1=<old>. Split on commas and accept the delivery when any value matches. Reading the secret with an API key needs the webhooks:read scope. You can also see it, and rotate it, in Settings → API Keys in the app.

Authorizations

Authorization
string
header
required

API key with the vd_sk_ prefix. Create keys from Settings, API Keys in the dashboard.

Response

Your signing secret.

secret
string

Your signing secret. Keep it private.

signature_header
string
Example:

"X-Valendata-Signature"

algorithm
string
Example:

"HMAC-SHA256 over '<timestamp>.<raw body>'"

previous_valid_until
string<date-time> | null

Set for 24 hours after a rotation: until then deliveries are also signed with the previous secret.

rotated_at
string<date-time> | null

When the secret was last rotated.