Stripe Payments & SaaS Billing Systems · Lektion

Webhook-Signaturen sicher verifizieren

Schützen Sie Ihr Payment-Backend vor gefälschten Ereignissen, indem Sie Stripe-Webhook-Signaturen validieren und sichere Praktiken für Endpunkte befolgen.

Lektion 4 von 413 Schritte

Webhook-Signaturen sicher verifizieren ist eine kostenlose Stripe Payments & SaaS Billing Systems-Lektion auf CoddyKit. Dies ist Lektion 4 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Stripe Payments & SaaS Billing Systems-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Stripe Payments & SaaS Billing Systems-Kurs umfasst insgesamt 4 Lektionen.

Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.

Why Verify Webhooks?

Your webhook endpoint is public. Without verification, an attacker could POST a fake payment_succeeded event and unlock paid features for free.

The Signing Secret

Each webhook endpoint has a signing secret (starts with whsec_). Stripe uses it to sign every event it sends you.

The Stripe-Signature Header

Every webhook request carries a Stripe-Signature header containing a timestamp and an HMAC signature of the payload.

// Stripe-Signature: t=1700000000,v1=5257a8...

Use the Raw Body

Signature verification needs the exact raw request body. If a framework parses JSON first, the bytes change and verification fails.

app.post('/webhook',
  express.raw({ type: 'application/json' }),
  handler
);

Verifying with the SDK

The Stripe SDK does the HMAC math for you via constructEvent.

function verify(rawBody, sig, secret, stripe) {
  return stripe.webhooks.constructEvent(rawBody, sig, secret);
}

Handling Verification Failure

If verification throws, reject the request with a 400. Never process an unverified event.

function process(ok) {
  if (!ok) return { status: 400, body: 'invalid signature' };
  return { status: 200, body: 'received' };
}
console.log(process(false));

Timestamp Tolerance

The signature includes a timestamp. Stripe rejects events older than a tolerance window to block replay attacks with captured payloads.

Constant-Time Comparison

Under the hood, signatures are compared in constant time to avoid timing attacks. The SDK handles this; never hand-roll a simple equality check.

Respond Fast, Process Later

Acknowledge with 200 quickly, then do heavy work asynchronously. Slow responses make Stripe retry and can cause duplicates.

Keep the Secret Safe

Store the signing secret in environment variables, never in source control. Rotate it if it leaks, using the dashboard.

const secret = process.env.STRIPE_WEBHOOK_SECRET;
console.log(Boolean(secret));

Per-Endpoint Secrets

Each registered endpoint has its own secret. Use the correct one for the URL receiving the event, especially across test and live modes.

Quick Check

Why must you use the raw request body for verification?

Recap

You secured your webhook endpoint:

  • Verify the Stripe-Signature with the signing secret
  • Use the raw body and the SDK constructEvent
  • Reject failures and rely on timestamp tolerance against replays
  • Keep secrets in env vars and respond fast
Kostenlos starten

Lerne Stripe Payments & SaaS Billing Systems mit einem KI-Tutor — kostenlos

Schreibe und führe echten Code in deinem Browser aus, bekomme sofortige Hilfe von einem 24/7 KI-Tutor und setze dein Lernen im Web oder in der App fort.

Kurse
12
Lektionen
48

Häufig gestellte Fragen

Ist die Lektion „Webhook-Signaturen sicher verifizieren“ kostenlos?

Ja — der vollständige Text von „Webhook-Signaturen sicher verifizieren“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Stripe Payments & SaaS Billing Systems-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Stripe Payments & SaaS Billing Systems-Kurs umfasst insgesamt 4 Lektionen.

Was lerne ich in „Webhook-Signaturen sicher verifizieren“?

Schützen Sie Ihr Payment-Backend vor gefälschten Ereignissen, indem Sie Stripe-Webhook-Signaturen validieren und sichere Praktiken für Endpunkte befolgen. Du übst Stripe Payments & SaaS Billing Systems mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.

Brauche ich Erfahrung, um Stripe Payments & SaaS Billing Systems zu starten?

Keine Vorkenntnisse erforderlich. Stripe Payments & SaaS Billing Systems auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 4 von 4.

Wie lange dauert die Lektion „Webhook-Signaturen sicher verifizieren“?

Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.

Kann ich in dieser Stripe Payments & SaaS Billing Systems-Lektion Code schreiben und ausführen?

Ja. Jede Stripe Payments & SaaS Billing Systems-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.

Alle Lektionen in diesem Kurs

  1. Zahlungsmethoden sicher speichern (Token)
  2. Strong Customer Authentication (SCA) implementieren
  3. Best Practices für PCI-Compliance in der Entwicklung
  4. Webhook-Signaturen sicher verifizieren
← Zurück zu Stripe Payments & SaaS Billing Systems