Verificare in sicurezza le firme dei webhook
Protegga il backend dei pagamenti dagli eventi contraffatti validando le firme dei webhook Stripe e seguendo pratiche sicure per gli endpoint.
Verificare in sicurezza le firme dei webhook è una lezione Stripe Payments & SaaS Billing Systems gratuita su CoddyKit. Questa è la lezione 4 di 4. Puoi leggere la lezione completa qui gratuitamente — poi esercitati direttamente nel browser con un editor di codice integrato e un tutor IA disponibile 24/7. Fa parte del percorso di apprendimento Stripe Payments & SaaS Billing Systems, e i tuoi progressi si sincronizzano tra il web e l'app CoddyKit. Il corso Stripe Payments & SaaS Billing Systems include 4 lezioni in totale.
Parti di questa lezione non sono ancora state tradotte e vengono mostrate in inglese.
Why Verify Webhooks?
Your webhook endpoint is public. Without verification, an attacker could POST a fake payment_succeeded event and unlock paid features for free.
The Signing Secret
Each webhook endpoint has a signing secret (starts with whsec_). Stripe uses it to sign every event it sends you.
The Stripe-Signature Header
Every webhook request carries a Stripe-Signature header containing a timestamp and an HMAC signature of the payload.
// Stripe-Signature: t=1700000000,v1=5257a8...Use the Raw Body
Signature verification needs the exact raw request body. If a framework parses JSON first, the bytes change and verification fails.
app.post('/webhook',
express.raw({ type: 'application/json' }),
handler
);Verifying with the SDK
The Stripe SDK does the HMAC math for you via constructEvent.
function verify(rawBody, sig, secret, stripe) {
return stripe.webhooks.constructEvent(rawBody, sig, secret);
}Handling Verification Failure
If verification throws, reject the request with a 400. Never process an unverified event.
function process(ok) {
if (!ok) return { status: 400, body: 'invalid signature' };
return { status: 200, body: 'received' };
}
console.log(process(false));Timestamp Tolerance
The signature includes a timestamp. Stripe rejects events older than a tolerance window to block replay attacks with captured payloads.
Constant-Time Comparison
Under the hood, signatures are compared in constant time to avoid timing attacks. The SDK handles this; never hand-roll a simple equality check.
Respond Fast, Process Later
Acknowledge with 200 quickly, then do heavy work asynchronously. Slow responses make Stripe retry and can cause duplicates.
Keep the Secret Safe
Store the signing secret in environment variables, never in source control. Rotate it if it leaks, using the dashboard.
const secret = process.env.STRIPE_WEBHOOK_SECRET;
console.log(Boolean(secret));Per-Endpoint Secrets
Each registered endpoint has its own secret. Use the correct one for the URL receiving the event, especially across test and live modes.
Quick Check
Why must you use the raw request body for verification?
Recap
You secured your webhook endpoint:
- Verify the Stripe-Signature with the signing secret
- Use the raw body and the SDK constructEvent
- Reject failures and rely on timestamp tolerance against replays
- Keep secrets in env vars and respond fast
Impara Stripe Payments & SaaS Billing Systems con un tutor IA — gratis
Scrivi ed esegui vero codice nel tuo browser, ricevi aiuto istantaneo da un tutor IA disponibile 24/7, e riprendi da dove hai lasciato sul web o nell'app.
- Corsi
- 12
- Lezioni
- 48
Domande Frequenti
La lezione «Verificare in sicurezza le firme dei webhook» è gratuita?
Sì — il testo completo di «Verificare in sicurezza le firme dei webhook» è gratuito qui sul web. Per esercitarvi in modo interattivo (un editor di codice integrato e un tutor IA 24/7) e sbloccare il resto del corso Stripe Payments & SaaS Billing Systems, passa a CoddyKit PRO. Il corso Stripe Payments & SaaS Billing Systems include 4 lezioni in totale.
Cosa imparerò in «Verificare in sicurezza le firme dei webhook»?
Protegga il backend dei pagamenti dagli eventi contraffatti validando le firme dei webhook Stripe e seguendo pratiche sicure per gli endpoint. Eserciti Stripe Payments & SaaS Billing Systems con codice pratico che esegui direttamente nel browser, e un tutor IA 24/7 risponde alle tue domande mentre lavori sulla lezione.
Ho bisogno di esperienza per iniziare Stripe Payments & SaaS Billing Systems?
Non è richiesta alcuna esperienza precedente. Stripe Payments & SaaS Billing Systems su CoddyKit è strutturato per principianti e studenti avanzati, quindi puoi iniziare da qui o dall'inizio e procedere al tuo ritmo. Questa è la lezione 4 di 4.
Quanto tempo richiede la lezione «Verificare in sicurezza le firme dei webhook»?
La maggior parte delle lezioni CoddyKit richiede circa 5–10 minuti. Ogni lezione è breve e interattiva, quindi fai progressi costanti e riprendi esattamente da dove hai lasciato su web e app.
Posso scrivere ed eseguire codice in questa lezione Stripe Payments & SaaS Billing Systems?
Sì. Ogni lezione Stripe Payments & SaaS Billing Systems include un editor di codice integrato, quindi scrivi ed esegui codice reale direttamente nel tuo browser e ricevi feedback istantaneo dall'IA — nessuna configurazione locale necessaria.
Tutte le lezioni di questo corso
- Archiviazione sicura dei metodi di pagamento (token)
- Implementazione della Strong Customer Authentication (SCA)
- Best practice per la conformità PCI degli sviluppatori
- Verificare in sicurezza le firme dei webhook