Webhook usage

Webhook signatures

Every webhook from Blink includes a signature so you can confirm the request really came from us and wasn't changed in transit. You'll need your webhook secret from the Blink Admin portal → App Identity screen. Keep this secret safe - treat it like a password.

Each webhook request includes an X-Signature header. It looks like this:

X-Signature: t=1788343266,v0=22b2b1ed18335c0b...,h=content-type x-event-id x-event-type,v1=1c8e5488dcbdf86e...

The header has four parts, separated by commas:

PartExampleWhat it is
tt=1788343266When the webhook was sent (Unix timestamp)
v0v0=22b2b1ed...Signature based on the timestamp and body
hh=content-type x-event-id x-event-typeWhich headers are included in the v1 signature
v1v1=1c8e5488...Signature based on the timestamp, headers, and body

Signature verification

For code examples and instructions on how to handle signature verification, please refer to Hook0 documentation: https://documentation.hook0.com/tutorials/webhook-authentication#step-2-basic-signature-verification.

For production applications, it is recommended that you use official Hook0 client: https://documentation.hook0.com/reference/sdk#the-clients