API & INTEGRATIONS
Verifying webhook signatures
Updated by Clustrix Admin · Jul 20, 2026 · 66 views
Headers we send:
X-Clustrix-Signature: t=TIMESTAMP,v1=HASHX-Clustrix-EventX-Clustrix-Delivery-Id
Verify it
$expected = hash_hmac("sha256", $rawBody, $signingSecret);\nif (!hash_equals($expected, $providedHash)) abort(400);
Was this helpful?
Thanks for the feedback!
We use cookies. Strictly necessary cookies keep the site working. We don't run third-party advertising trackers.