0Pricing
Stripe Payments & SaaS Billing Systems · Lección

Verificación segura de firmas de webhooks

Proteja su backend de pagos frente a eventos falsificados validando las firmas de los webhooks de Stripe y siguiendo prácticas seguras para endpoints.

Verificación segura de firmas de webhooks es una lección gratuita de Stripe Payments & SaaS Billing Systems en CoddyKit. Esta es la lección 4 de 4. Puedes leer la lección completa abajo gratuitamente — luego la practicas en el navegador con un editor de código integrado y un tutor de IA 24/7. Forma parte de la ruta de aprendizaje de Stripe Payments & SaaS Billing Systems, y tu progreso se sincroniza en la web y la app de CoddyKit. El curso de Stripe Payments & SaaS Billing Systems incluye 4 lecciones en total.

Partes de esta lección aún no han sido traducidas y se muestran en inglés.

Why Verify Webhooks?

Your webhook endpoint is public. Without verification, an attacker could POST a fake payment_succeeded event and unlock paid features for free.

The Signing Secret

Each webhook endpoint has a signing secret (starts with whsec_). Stripe uses it to sign every event it sends you.

The Stripe-Signature Header

Every webhook request carries a Stripe-Signature header containing a timestamp and an HMAC signature of the payload.

// Stripe-Signature: t=1700000000,v1=5257a8...

Use the Raw Body

Signature verification needs the exact raw request body. If a framework parses JSON first, the bytes change and verification fails.

app.post('/webhook',
  express.raw({ type: 'application/json' }),
  handler
);

Verifying with the SDK

The Stripe SDK does the HMAC math for you via constructEvent.

function verify(rawBody, sig, secret, stripe) {
  return stripe.webhooks.constructEvent(rawBody, sig, secret);
}

Handling Verification Failure

If verification throws, reject the request with a 400. Never process an unverified event.

function process(ok) {
  if (!ok) return { status: 400, body: 'invalid signature' };
  return { status: 200, body: 'received' };
}
console.log(process(false));

Timestamp Tolerance

The signature includes a timestamp. Stripe rejects events older than a tolerance window to block replay attacks with captured payloads.

Constant-Time Comparison

Under the hood, signatures are compared in constant time to avoid timing attacks. The SDK handles this; never hand-roll a simple equality check.

Respond Fast, Process Later

Acknowledge with 200 quickly, then do heavy work asynchronously. Slow responses make Stripe retry and can cause duplicates.

Keep the Secret Safe

Store the signing secret in environment variables, never in source control. Rotate it if it leaks, using the dashboard.

const secret = process.env.STRIPE_WEBHOOK_SECRET;
console.log(Boolean(secret));

Per-Endpoint Secrets

Each registered endpoint has its own secret. Use the correct one for the URL receiving the event, especially across test and live modes.

Quick Check

Why must you use the raw request body for verification?

Recap

You secured your webhook endpoint:

  • Verify the Stripe-Signature with the signing secret
  • Use the raw body and the SDK constructEvent
  • Reject failures and rely on timestamp tolerance against replays
  • Keep secrets in env vars and respond fast

Preguntas frecuentes

¿La lección «Verificación segura de firmas de webhooks» es gratis?

Sí — el texto completo de «Verificación segura de firmas de webhooks» es gratis para leer aquí en la web. Para practicarla de forma interactiva (editor de código integrado y tutor de IA 24/7) y desbloquear el resto del curso de Stripe Payments & SaaS Billing Systems, actualiza a CoddyKit PRO. El curso de Stripe Payments & SaaS Billing Systems incluye 4 lecciones en total.

¿Qué aprenderé en «Verificación segura de firmas de webhooks»?

Proteja su backend de pagos frente a eventos falsificados validando las firmas de los webhooks de Stripe y siguiendo prácticas seguras para endpoints. Practicas Stripe Payments & SaaS Billing Systems con código real que ejecutas directamente en el navegador, y un tutor de IA 24/7 responde tus preguntas mientras trabajas en la lección.

¿Necesito experiencia previa para empezar Stripe Payments & SaaS Billing Systems?

No se requiere experiencia previa. Stripe Payments & SaaS Billing Systems en CoddyKit está estructurado para principiantes hasta estudiantes avanzados, así que puedes empezar aquí o desde el inicio y avanzar a tu ritmo. Esta es la lección 4 de 4.

¿Cuánto tiempo toma la lección «Verificación segura de firmas de webhooks»?

La mayoría de las lecciones de CoddyKit toman alrededor de 5–10 minutos. Cada una es compacta e interactiva, así que avanzas constantemente y retomas exactamente por donde dejaste en la web y la app.

¿Puedo escribir y ejecutar código en esta lección de Stripe Payments & SaaS Billing Systems?

Sí. Cada lección de Stripe Payments & SaaS Billing Systems incluye un editor de código integrado, así que escribes y ejecutas código real directamente en tu navegador y obtienes retroalimentación instantánea de IA — sin configuración local necesaria.

Todas las lecciones de este curso

  1. Almacenamiento seguro de métodos de pago (tokens)
  2. Implementación de la autenticación reforzada de clientes (SCA)
  3. Prácticas recomendadas de cumplimiento de PCI para desarrolladores
  4. Verificación segura de firmas de webhooks
← Volver a Stripe Payments & SaaS Billing Systems