Skip to main content
Each call has an X-Email-Engine-Signature header:
The part after sha256= is the HMAC-SHA256 of the raw request body, keyed with the endpoint’s secret, in hex. You get the secret when you create the endpoint. Compute it yourself and compare. Reject the call if they differ.
Use the raw body exactly as received. If you parse the JSON and encode it again, the bytes change and the signature won’t match.
Use a constant-time comparison (hash_equals, timingSafeEqual, compare_digest), as above. You can also add your own header when you create the endpoint, such as Authorization: Bearer …, and check it.