Developer docs

Webhook signature verification

Linkube signs webhook deliveries with HMAC-SHA256. Verify the exact raw request body before trusting a webhook event.

Headers

  • X-Linkube-Timestamp is a Unix timestamp in seconds.
  • X-Linkube-Signature is the hex HMAC-SHA256 digest.
  • The signed message format is {timestamp}:{rawBody}.

Example payload

jsonlink.created
{
  "event": "link.created",
  "data": {
    "id": "lnk_abc123xyz789",
    "short_code": "summer-sale",
    "destination_url": "https://example.com/pricing"
  }
}

Retries and failures

  • Linkube attempts each webhook delivery up to 3 times.
  • Retry backoff is bounded: first retry after 60 seconds, second retry after 300 seconds.
  • After the final failed attempt, the delivery is marked dead_lettered for operator review.
  • Return a 2xx response only after your endpoint has durably accepted the event.

Node.js verification

javascriptHMAC-SHA256
import crypto from "node:crypto";

function verifyLinkubeWebhook({ rawBody, timestamp, signature, secret }) {
  const message = `${timestamp}:${rawBody}`;
  const expected = crypto
    .createHmac("sha256", secret)
    .update(message, "utf8")
    .digest("hex");

  return crypto.timingSafeEqual(
    Buffer.from(signature, "hex"),
    Buffer.from(expected, "hex")
  );
}

Keep your webhook secret outside source control. Reject events with stale timestamps according to your own replay-window policy.