Verificando assinaturas de Webhooks com segurança
Proteja seu back-end de pagamentos contra eventos falsificados validando as assinaturas de Webhooks do Stripe e seguindo práticas seguras para endpoints.
Verificando assinaturas de Webhooks com segurança é uma aula grátis de Stripe Payments & SaaS Billing Systems no CoddyKit. Esta é a aula 4 de 4. Você pode ler a aula completa abaixo gratuitamente — depois pratica ao vivo no navegador com um editor de código integrado e um tutor de IA 24/7. Faz parte do caminho de aprendizado de Stripe Payments & SaaS Billing Systems, e seu progresso é sincronizado entre a web e o app CoddyKit. O curso de Stripe Payments & SaaS Billing Systems inclui 4 aulas no total.
Partes desta aula ainda não foram traduzidas e aparecem em inglês.
Why Verify Webhooks?
Your webhook endpoint is public. Without verification, an attacker could POST a fake payment_succeeded event and unlock paid features for free.
The Signing Secret
Each webhook endpoint has a signing secret (starts with whsec_). Stripe uses it to sign every event it sends you.
The Stripe-Signature Header
Every webhook request carries a Stripe-Signature header containing a timestamp and an HMAC signature of the payload.
// Stripe-Signature: t=1700000000,v1=5257a8...Use the Raw Body
Signature verification needs the exact raw request body. If a framework parses JSON first, the bytes change and verification fails.
app.post('/webhook',
express.raw({ type: 'application/json' }),
handler
);Verifying with the SDK
The Stripe SDK does the HMAC math for you via constructEvent.
function verify(rawBody, sig, secret, stripe) {
return stripe.webhooks.constructEvent(rawBody, sig, secret);
}Handling Verification Failure
If verification throws, reject the request with a 400. Never process an unverified event.
function process(ok) {
if (!ok) return { status: 400, body: 'invalid signature' };
return { status: 200, body: 'received' };
}
console.log(process(false));Timestamp Tolerance
The signature includes a timestamp. Stripe rejects events older than a tolerance window to block replay attacks with captured payloads.
Constant-Time Comparison
Under the hood, signatures are compared in constant time to avoid timing attacks. The SDK handles this; never hand-roll a simple equality check.
Respond Fast, Process Later
Acknowledge with 200 quickly, then do heavy work asynchronously. Slow responses make Stripe retry and can cause duplicates.
Keep the Secret Safe
Store the signing secret in environment variables, never in source control. Rotate it if it leaks, using the dashboard.
const secret = process.env.STRIPE_WEBHOOK_SECRET;
console.log(Boolean(secret));Per-Endpoint Secrets
Each registered endpoint has its own secret. Use the correct one for the URL receiving the event, especially across test and live modes.
Quick Check
Why must you use the raw request body for verification?
Recap
You secured your webhook endpoint:
- Verify the Stripe-Signature with the signing secret
- Use the raw body and the SDK constructEvent
- Reject failures and rely on timestamp tolerance against replays
- Keep secrets in env vars and respond fast
Perguntas Frequentes
A aula “Verificando assinaturas de Webhooks com segurança” é grátis?
Sim — o texto completo de “Verificando assinaturas de Webhooks com segurança” é grátis para ler aqui na web. Para praticá-la interativamente (um editor de código integrado e um tutor de IA 24/7) e desbloquear o restante do curso de Stripe Payments & SaaS Billing Systems, atualize para CoddyKit PRO. O curso de Stripe Payments & SaaS Billing Systems inclui 4 aulas no total.
O que vou aprender em “Verificando assinaturas de Webhooks com segurança”?
Proteja seu back-end de pagamentos contra eventos falsificados validando as assinaturas de Webhooks do Stripe e seguindo práticas seguras para endpoints. Você pratica Stripe Payments & SaaS Billing Systems com código prático que executa diretamente no navegador, e um tutor de IA 24/7 responde suas dúvidas enquanto trabalha na aula.
Preciso ter experiência prévia para começar Stripe Payments & SaaS Billing Systems?
Nenhuma experiência prévia é necessária. Stripe Payments & SaaS Billing Systems no CoddyKit é estruturado para alunos iniciantes até avançados, então você pode começar aqui ou desde o início e aprender no seu ritmo. Esta é a aula 4 de 4.
Quanto tempo leva a aula “Verificando assinaturas de Webhooks com segurança”?
A maioria das aulas CoddyKit leva cerca de 5–10 minutos. Cada uma é compacta e interativa, então você faz progresso constante e retoma exatamente de onde parou entre web e app.
Posso escrever e executar código nesta aula de Stripe Payments & SaaS Billing Systems?
Sim. Cada aula de Stripe Payments & SaaS Billing Systems inclui um editor de código integrado, então você escreve e executa código real direto no navegador e recebe feedback de IA instantaneamente — nenhuma configuração local necessária.
Todas as aulas deste curso
- Armazenamento seguro de métodos de pagamento (tokens)
- Implementação da autenticação forte do cliente (SCA)
- Melhores práticas de conformidade com PCI para desenvolvedores
- Verificando assinaturas de Webhooks com segurança