# Webhook Signature Validator (`junipr/webhook-signature-validator`) Actor

Validate webhook payload signatures against HMAC-style schemes and return pass/fail details.

- **URL**: https://apify.com/junipr/webhook-signature-validator.md
- **Developed by:** [junipr](https://apify.com/junipr) (community)
- **Categories:** Developer tools, E-commerce
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $6.50 / 1,000 signature validateds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

## Webhook Signature Validator

### Store Positioning

**Store title:** Webhook Signature Validator

**Short description:** Validate webhook payload signatures against HMAC-style schemes and return pass/fail details.

**SEO title:** Webhook Signature Validator — API, schema, and developer QA

**SEO description:** Validate webhook payload signatures against HMAC-style schemes and return pass/fail details. Use it to catch contract drift, schema mistakes, unsafe endpoint assumptions, and developer-tool quality issues before release.

**Categories:** DEVELOPER\_TOOLS, ECOMMERCE

**Keywords:** webhook, signature, validator, web audit, api/developer qa

### Fixed-Inclusive PPE Pricing

This actor uses pay-per-event pricing. Event prices include Apify platform usage; users are not expected to pay a separate platform-usage pass-through charge for the configured pricing model.

- Tier: A1 — API/developer QA
- Primary event: `signature-validated` at $0.00650 base
- Default max charge: $10.00
- Store discounts: FREE/BRONZE base, SILVER discounted, GOLD deepest approved discount

Event set:

- `actor-start`: base $0.00500, GOLD $0.00400. Webhook Signature Validator: charged when actor start is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
- `signature-validated`: base $0.00650, GOLD $0.00520. Webhook Signature Validator: charged when signature validated is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
- `contract-rule-checked`: base $0.00390, GOLD $0.00312. Webhook Signature Validator: charged when contract rule checked is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
- `report-generated`: base $0.05000, GOLD $0.04000. Webhook Signature Validator: charged when report generated is completed. The price includes Apify platform usage; no separate usage pass-through is intended.

### Public Task Concepts

- Validate Webhook Signature records from a capped sample
- Find invalid Webhook Signature values before delivery
- Check Webhook Signature coverage against expected rules
- Prioritize Webhook Signature validation failures by severity
- Export Webhook Signature pass-fail rows with evidence

### What It Does

Validate webhook payload signatures against HMAC-style schemes and return pass/fail details.

This local package is part of the Junipr Apify actors 171-200 premium build for ChatGPT review.

### What It Does Not Do

- It does not call live Apify APIs.
- It does not publish, upload Store assets, create public tasks, or configure live PPE.
- It does not claim publish readiness.
- It does not make unbounded network calls in the supplied examples path.

### Input Fields

Seed shape: inputItems, maxItems, includeReport

The tiny fixture is available at `examples/input.tiny.json` and mirrored at `fixtures/input.tiny.json` for the local runner.

### Output Fields

- `validationId`
- `algorithm`
- `signatureProvided`
- `signatureComputedMasked`
- `isValid`
- `timestampValid`
- `payloadHash`
- `mismatchReason`

### Public Task Examples

#### Validate webhook HMAC signatures from sample payloads

- Search intent: validate webhook hmac signatures from sample payloads
- Specific input: Fixture input shaped for validate webhook hmac signatures from sample payloads.
- Expected output: Dataset rows with validationId, algorithm, signatureProvided, signatureComputedMasked plus local KVS report evidence.
- Why run it: API teams, integration engineers, SaaS developers would run this to get a bounded local proof before any live Apify review or production use.

#### Mask computed webhook secrets in QA output

- Search intent: mask computed webhook secrets in qa output
- Specific input: Fixture input shaped for mask computed webhook secrets in qa output.
- Expected output: Dataset rows with validationId, algorithm, signatureProvided, signatureComputedMasked plus local KVS report evidence.
- Why run it: API teams, integration engineers, SaaS developers would run this to get a bounded local proof before any live Apify review or production use.

#### Compare provided and computed webhook signatures

- Search intent: compare provided and computed webhook signatures
- Specific input: Fixture input shaped for compare provided and computed webhook signatures.
- Expected output: Dataset rows with validationId, algorithm, signatureProvided, signatureComputedMasked plus local KVS report evidence.
- Why run it: API teams, integration engineers, SaaS developers would run this to get a bounded local proof before any live Apify review or production use.

#### Check timestamp and payload hash evidence locally

- Search intent: check timestamp and payload hash evidence locally
- Specific input: Fixture input shaped for check timestamp and payload hash evidence locally.
- Expected output: Dataset rows with validationId, algorithm, signatureProvided, signatureComputedMasked plus local KVS report evidence.
- Why run it: API teams, integration engineers, SaaS developers would run this to get a bounded local proof before any live Apify review or production use.

#### Prepare webhook signature fixtures for integration tests

- Search intent: prepare webhook signature fixtures for integration tests
- Specific input: Fixture input shaped for prepare webhook signature fixtures for integration tests.
- Expected output: Dataset rows with validationId, algorithm, signatureProvided, signatureComputedMasked plus local KVS report evidence.
- Why run it: API teams, integration engineers, SaaS developers would run this to get a bounded local proof before any live Apify review or production use.

### Tests

- Actor-specific fixture tests live in `test/webhook-signature-validator.test.ts`.
- Node-based local suites validate dataset schema conformance, output samples, local smoke runs, and PPE guard behavior.

### FAQ

#### Is this live on Apify?

No. This is a local package for ChatGPT review only.

#### Is it publish-ready?

No. It needs later live tiny-run validation and console configuration before any publication decision.

# Actor input Schema

## `inputItems` (type: `array`):

Actor-specific records or URLs to process.

## `domains` (type: `array`):

Domain fixture records or domain strings.

## `urls` (type: `array`):

URL fixture records or URL strings.

## `maxItems` (type: `integer`):

Hard cap for processed items.

## `maxDomains` (type: `integer`):

Hard cap for processed domains.

## `timeoutMs` (type: `integer`):

Local/live request timeout cap in milliseconds.

## `includeReport` (type: `boolean`):

Write KVS Markdown and JSON report outputs.

## `includeSummary` (type: `boolean`):

Write summary KVS output.

## `strictMode` (type: `boolean`):

Use stricter validation thresholds.

## `fixtureMode` (type: `boolean`):

Use local deterministic fixtures. Live lookups remain off by default.

## `maxChargeUsd` (type: `number`):

Local PPE guard cap before paid rows stop gracefully.

## Actor input object example

```json
{
  "maxItems": 50,
  "maxDomains": 50,
  "timeoutMs": 5000,
  "includeReport": true,
  "includeSummary": true,
  "strictMode": false,
  "fixtureMode": true,
  "maxChargeUsd": 1
}
```

# Actor output Schema

## `dataset` (type: `string`):

Structured rows emitted by the actor.

## `report` (type: `string`):

Run summary report stored in the default key-value store.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {};

// Run the Actor and wait for it to finish
const run = await client.actor("junipr/webhook-signature-validator").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {}

# Run the Actor and wait for it to finish
run = client.actor("junipr/webhook-signature-validator").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{}' |
apify call junipr/webhook-signature-validator --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=junipr/webhook-signature-validator",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/2RGj11DefwCsCfBBP/builds/jUNkgH7x6IQnij47f/openapi.json
