Verificación segura de firmas de webhooks
Proteja su backend de pagos frente a eventos falsificados validando las firmas de los webhooks de Stripe y siguiendo prácticas seguras para endpoints.
Verificación segura de firmas de webhooks es una lección gratuita de Stripe Payments & SaaS Billing Systems en CoddyKit. Esta es la lección 4 de 4. Puedes leer la lección completa abajo gratuitamente — luego la practicas en el navegador con un editor de código integrado y un tutor de IA 24/7. Forma parte de la ruta de aprendizaje de Stripe Payments & SaaS Billing Systems, y tu progreso se sincroniza en la web y la app de CoddyKit. El curso de Stripe Payments & SaaS Billing Systems incluye 4 lecciones en total.
Partes de esta lección aún no han sido traducidas y se muestran en inglés.
Why Verify Webhooks?
Your webhook endpoint is public. Without verification, an attacker could POST a fake payment_succeeded event and unlock paid features for free.
The Signing Secret
Each webhook endpoint has a signing secret (starts with whsec_). Stripe uses it to sign every event it sends you.
The Stripe-Signature Header
Every webhook request carries a Stripe-Signature header containing a timestamp and an HMAC signature of the payload.
// Stripe-Signature: t=1700000000,v1=5257a8...Use the Raw Body
Signature verification needs the exact raw request body. If a framework parses JSON first, the bytes change and verification fails.
app.post('/webhook',
express.raw({ type: 'application/json' }),
handler
);Verifying with the SDK
The Stripe SDK does the HMAC math for you via constructEvent.
function verify(rawBody, sig, secret, stripe) {
return stripe.webhooks.constructEvent(rawBody, sig, secret);
}Handling Verification Failure
If verification throws, reject the request with a 400. Never process an unverified event.
function process(ok) {
if (!ok) return { status: 400, body: 'invalid signature' };
return { status: 200, body: 'received' };
}
console.log(process(false));Timestamp Tolerance
The signature includes a timestamp. Stripe rejects events older than a tolerance window to block replay attacks with captured payloads.
Constant-Time Comparison
Under the hood, signatures are compared in constant time to avoid timing attacks. The SDK handles this; never hand-roll a simple equality check.
Respond Fast, Process Later
Acknowledge with 200 quickly, then do heavy work asynchronously. Slow responses make Stripe retry and can cause duplicates.
Keep the Secret Safe
Store the signing secret in environment variables, never in source control. Rotate it if it leaks, using the dashboard.
const secret = process.env.STRIPE_WEBHOOK_SECRET;
console.log(Boolean(secret));Per-Endpoint Secrets
Each registered endpoint has its own secret. Use the correct one for the URL receiving the event, especially across test and live modes.
Quick Check
Why must you use the raw request body for verification?
Recap
You secured your webhook endpoint:
- Verify the Stripe-Signature with the signing secret
- Use the raw body and the SDK constructEvent
- Reject failures and rely on timestamp tolerance against replays
- Keep secrets in env vars and respond fast
Preguntas frecuentes
¿La lección «Verificación segura de firmas de webhooks» es gratis?
Sí — el texto completo de «Verificación segura de firmas de webhooks» es gratis para leer aquí en la web. Para practicarla de forma interactiva (editor de código integrado y tutor de IA 24/7) y desbloquear el resto del curso de Stripe Payments & SaaS Billing Systems, actualiza a CoddyKit PRO. El curso de Stripe Payments & SaaS Billing Systems incluye 4 lecciones en total.
¿Qué aprenderé en «Verificación segura de firmas de webhooks»?
Proteja su backend de pagos frente a eventos falsificados validando las firmas de los webhooks de Stripe y siguiendo prácticas seguras para endpoints. Practicas Stripe Payments & SaaS Billing Systems con código real que ejecutas directamente en el navegador, y un tutor de IA 24/7 responde tus preguntas mientras trabajas en la lección.
¿Necesito experiencia previa para empezar Stripe Payments & SaaS Billing Systems?
No se requiere experiencia previa. Stripe Payments & SaaS Billing Systems en CoddyKit está estructurado para principiantes hasta estudiantes avanzados, así que puedes empezar aquí o desde el inicio y avanzar a tu ritmo. Esta es la lección 4 de 4.
¿Cuánto tiempo toma la lección «Verificación segura de firmas de webhooks»?
La mayoría de las lecciones de CoddyKit toman alrededor de 5–10 minutos. Cada una es compacta e interactiva, así que avanzas constantemente y retomas exactamente por donde dejaste en la web y la app.
¿Puedo escribir y ejecutar código en esta lección de Stripe Payments & SaaS Billing Systems?
Sí. Cada lección de Stripe Payments & SaaS Billing Systems incluye un editor de código integrado, así que escribes y ejecutas código real directamente en tu navegador y obtienes retroalimentación instantánea de IA — sin configuración local necesaria.
Todas las lecciones de este curso
- Almacenamiento seguro de métodos de pago (tokens)
- Implementación de la autenticación reforzada de clientes (SCA)
- Prácticas recomendadas de cumplimiento de PCI para desarrolladores
- Verificación segura de firmas de webhooks