Message verification

Message verification

As a security pattern, each webhook and its metadata is signed with a unique key for each endpoint. This signature can be used to verify that the webhook really comes from OrkestaPay, and to only process it if the origin is valid. Each webhook call includes three headers with additional information that are used for verification:

  • svix-id: Unique identifier of the webhook message. This identifier is unique across all messages.
  • svix-signature: Base64 encoded signature.
  • svix-timestamp: Epoch timestamp.

To perform the validation, the secret signature is required.


Webhook signature

Each notification sent is signed as a security measure. The Webhook signature allows the merchant to validate the origin of the notifications and process notifications with a valid origin. To perform the validation, the secret signature of your endpoint is required.

Once your endpoint is configured, you can obtain the secret signature in the endpoints section by selecting your configured endpoint.

You can consult the official documentation of our provider by clicking here, which has libraries in the most popular programming languages.

Verification example

The following verification example is done with NodeJS.

The Svix library must be installed:

npm install svix
// Or
yarn add svix
import { Webhook } from "svix";

const secret = "whsec_MfKQ9r8GKYqrTwjUPD8ILPZIo2LaLaSw";

// The headers are sent with each notification
const headers = {
  "svix-id": "msg_p5jXN8AQM9LWM0D4loKWxJek",
  "svix-timestamp": "1614265330",
  "svix-signature": "v1,g0hM9SsE+OTPJTGt/tmIKtSyZlE3uFJELVlNIOLJ1OE=",
};
const payload =
  '{"algorithm":"RSA","encryptedData":"z7YjgSyx0VzXlDGNC4fjjk1IC69qKN8rRLSItUDY9WXQFgr98ORq/ieJunuCucwk6hmrM9CZAlszE/LD/qSeUtOUcv28ngjobZ5UD+zDqLOeqC5KqHtP0I48L1wC+epXMntsd/KxslWh0+s076K8hZFg7dgJOy2HS46tytNX7AAbEzuQouQo3R0OGV//asG3POej3VQTyRTzKVoRDOO7cVGgNenI4AjfAjUJu+gcOzHqrAj5qr92TEZOZf45+pAk6p5nrfL42NBThO8GB3pXQr2/k74HpkFmVXcZJRB7RDSGfhsFCsnDFZ4N4mHQJWc1/u00z7oGzymPSDGQBEUjzIwGbjBLLDHxdCGKWuwdUq5hAH8Nk55HGOycou7ciBBXOl8E3iTaSxldqOkFLpvkMQ6G2i6dH/1ERKxx61LtQveetkGGMPaLRlsgrUGJNftuKNGEMMQgxn4JykppxHqW3KBlzNhpFUn3QELIctk5SoV12XUDVWi4yhd49F0QlbqfDbRN7ogXo12/SYhUEBS4Wa2uo/mtVKkAdo+GYLtgcggP25y+Qw/I5CenBMJtm2mVFi1b/9AwPaDQo+Yd4S7SrGPyhvcRJcSareIyCXIFSDq6j40qPxGclUv0MLHdwiqxcmmiCP9PQwSnKstCNPBx+IN91E6UfnyBYBhXOWFPZqyHG5OtdBfrx9pIa+0TtFiMBbVGUDidj5QkslyLOZ5Zhx+RMOz+47GpiSg9LaObfJdH4vRsbsZgufvt5hceGE6+lUn3zQzTcwPLaEsQv4HsNMEUKW+tt8K6ZB3GLWaWtII4g0gVlQi2T5P4ZsvBFXf2YJFj4cAL21JVcRanjD2vYk0SbYyuOM2fpBtMJR8pIbVTzdyEw3pPQdyHo4LlbYBFkM3DaXxum9qHr2MHFeAefwJRM79ou5laulfj4nqBPi6hhfT1Z9r9ToDPujOtH+0jRnTIPs4zAWY6rXzUivPJkcu3iqUsqCZcQaU5SHhKli/bHakINyRyTd1ozpdrMsE3rn2VorpgJyVDT47/Bh+xG0F8lCZKofgh4w7DTRxOcIJwkUaPqu30lHHbmc8q0JfGXOgTc496TyjdFx4R529DMzDDkSCVFKp3z8qnG46WsIOIGCp2OXvIiSIihyQFO3FnBx16NbdVlicnTwov4TUPRcsYDIx0p33c3hxOmn1RR1aygYx7XvG3tuMS8ktpfq12ENy3zwpeOit1b8ylnBHwEdaAENaVy03TOLMxIj8rZSfj2AXhnwAKPMLE1AWKufE7OkQAGg2JyJ/H5wB69k9FjwmG0UbkpDGCHNKTMSmwWC6ppV08g/VqUxP50cgXdk19u7Atr1AjCmDXdkFJXYeYwg==","flatData":"","keySize":4096}"';
const wh = new Webhook(secret);
// Throws an exception on error, returns verified content on success
const payload = wh.verify(payload, headers);

You can also perform the verification manually, without using libraries. Consult the official documentation of our provider by clicking here.

📘

NOTE

It is necessary to use the raw request body when verifying webhooks, since the cryptographic signature is sensitive even to the slightest changes. You must be careful with frameworks that parse the request as JSON because this will also break the signature verification.


Validation of source IP addresses

In case your webhook receiving endpoint contains a firewall or NAT configuration, consider allowing traffic from the following list of IP addresses to receive notifications from OrkestaPay.

  • 54.216.8.72
  • 54.173.54.49
  • 52.215.16.239
  • 52.55.123.25
  • 52.6.93.106
  • 63.33.109.123
  • 44.228.126.217
  • 50.112.21.217
  • 52.24.126.164
  • 54.148.139.208