> For the complete documentation index, see [llms.txt](https://docs.partssource.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.partssource.com/webhooks/verifying-deliveries.md).

# Verifying Deliveries

The normative signature specification and reference implementations

## The signature specification

**Signed content:** `<X-PS-Timestamp value>.<raw request body bytes>`

**Algorithm:** HMAC-SHA256, hex-encoded; key = your endpoint secret

**Reject if:** the timestamp is more than 300 seconds from now, or the signature differs (compare in constant time)

**Common failure:** verifying against a re-parsed or re-serialized body. Verify the exact bytes received, before any JSON parsing.

## Reference implementations

{% tabs %}
{% tab title="Node" %}

```javascript
const express = require('express');
const crypto = require('crypto');
const app = express();

app.post('/webhooks/partssource',
  // Keep the raw bytes. Do not use express.json() on this route:
  // the signature covers the body exactly as sent.
  express.raw({ type: 'application/json' }),
  (req, res) => {
    const signature = req.headers['x-ps-signature'] ?? '';
    const timestamp = req.headers['x-ps-timestamp'] ?? '';

    // Reject deliveries older than five minutes (replay protection).
    if (Math.abs(Date.now() / 1000 - Number(timestamp)) > 300) {
      return res.status(401).end();
    }

    // Verify HMAC-SHA256 over "<timestamp>.<raw body>" in constant time.
    const expected = crypto
      .createHmac('sha256', process.env.PS_WEBHOOK_SECRET)
      .update(`${timestamp}.${req.body}`)
      .digest('hex');
    const a = Buffer.from(signature);
    const b = Buffer.from(expected);
    if (a.length !== b.length || !crypto.timingSafeEqual(a, b)) {
      return res.status(401).end();
    }

    // Acknowledge immediately; process asynchronously.
    res.status(200).end();
    queue.push(JSON.parse(req.body));
  });
```

{% endtab %}

{% tab title="C#" %}

```csharp
app.MapPost("/webhooks/partssource", async (HttpRequest req) =>
{
    using var reader = new StreamReader(req.Body);
    var body = await reader.ReadToEndAsync(); // raw body, before any model binding

    var signature = req.Headers["X-PS-Signature"].ToString();
    var timestamp = req.Headers["X-PS-Timestamp"].ToString();

    if (!long.TryParse(timestamp, out var ts) ||
        Math.Abs(DateTimeOffset.UtcNow.ToUnixTimeSeconds() - ts) > 300)
        return Results.Unauthorized();

    var secret = Environment.GetEnvironmentVariable("PS_WEBHOOK_SECRET")!;
    using var hmac = new HMACSHA256(Encoding.UTF8.GetBytes(secret));
    var expected = Convert.ToHexString(
        hmac.ComputeHash(Encoding.UTF8.GetBytes($"{timestamp}.{body}"))).ToLowerInvariant();

    if (!CryptographicOperations.FixedTimeEquals(
            Encoding.UTF8.GetBytes(expected), Encoding.UTF8.GetBytes(signature)))
        return Results.Unauthorized();

    await queue.EnqueueAsync(body); // process asynchronously
    return Results.Ok();
});
```

{% endtab %}

{% tab title="Python" %}

```python
@app.post("/webhooks/partssource")
def webhook():
    raw = request.get_data()  # raw bytes, before any JSON parsing
    signature = request.headers.get("X-PS-Signature", "")
    timestamp = request.headers.get("X-PS-Timestamp", "0")

    if abs(time.time() - float(timestamp)) > 300:
        abort(401)

    expected = hmac.new(
        os.environ["PS_WEBHOOK_SECRET"].encode(),
        f"{timestamp}.".encode() + raw,
        hashlib.sha256,
    ).hexdigest()

    if not hmac.compare_digest(expected, signature):
        abort(401)

    queue.enqueue(raw)  # process asynchronously
    return "", 200
```

{% endtab %}
{% endtabs %}

{% hint style="info" %}
Every other page links here rather than restating this specification. If a sample and this specification ever disagree, the specification wins.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.partssource.com/webhooks/verifying-deliveries.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
