The signed value is:
Node.js example
X-Collabos-Delivery.Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Verify that a webhook delivery came from CollabOS.
| Header | Purpose |
|---|---|
X-CollabOS-Event | Event type |
X-Collabos-Delivery | Delivery identifier |
X-Collabos-Timestamp | Unix timestamp used in the signature |
X-Collabos-Signature | Signature in the form v1=<hex> |
{timestamp}.{rawBody}
v1=HMAC_SHA256(endpoint_secret, "{timestamp}.{rawBody}")
import crypto from 'node:crypto';
export function verifyCollabOSWebhook({ rawBody, timestamp, signature, secret }) {
const expected = `v1=${crypto
.createHmac('sha256', secret)
.update(`${timestamp}.${rawBody}`)
.digest('hex')}`;
const expectedBytes = Buffer.from(expected);
const signatureBytes = Buffer.from(signature ?? '');
return (
expectedBytes.length === signatureBytes.length &&
crypto.timingSafeEqual(expectedBytes, signatureBytes)
);
}
X-Collabos-Delivery.