Developer docs
Webhook signature verification
Linkube signs webhook deliveries with HMAC-SHA256. Verify the exact raw request body before trusting a webhook event.
Headers
X-Linkube-Timestampis a Unix timestamp in seconds.X-Linkube-Signatureis the hex HMAC-SHA256 digest.- The signed message format is
{timestamp}:{rawBody}.
Example payload
jsonlink.created
{
"event": "link.created",
"data": {
"id": "lnk_abc123xyz789",
"short_code": "summer-sale",
"destination_url": "https://example.com/pricing"
}
}Retries and failures
- Linkube attempts each webhook delivery up to 3 times.
- Retry backoff is bounded: first retry after 60 seconds, second retry after 300 seconds.
- After the final failed attempt, the delivery is marked
dead_letteredfor operator review. - Return a 2xx response only after your endpoint has durably accepted the event.
Node.js verification
javascriptHMAC-SHA256
import crypto from "node:crypto";
function verifyLinkubeWebhook({ rawBody, timestamp, signature, secret }) {
const message = `${timestamp}:${rawBody}`;
const expected = crypto
.createHmac("sha256", secret)
.update(message, "utf8")
.digest("hex");
return crypto.timingSafeEqual(
Buffer.from(signature, "hex"),
Buffer.from(expected, "hex")
);
}Keep your webhook secret outside source control. Reject events with stale timestamps according to your own replay-window policy.