# Unable to verify webhook signature on Node.JS

**URL:** <https://community.rapyd.net/t/unable-to-verify-webhook-signature-on-node-js/58836>\
**Category:** 🙋🏽‍♀️🙋🏽‍♂️ Ask Questions\
**Tags:** webhooks\
**Created:** [August 21, 2023, 9:26am UTC](https://community.rapyd.net/t/unable-to-verify-webhook-signature-on-node-js/58836 "2023-08-21T09:26:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![nettle\_kieran](https://sea2.discourse-cdn.com/flex016/user_avatar/community.rapyd.net/nettle_kieran/32/22076_2.png) [@nettle\_kieran](https://community.rapyd.net/u/nettle_kieran)\
**Post date:** [August 21, 2023, 9:26am UTC](https://community.rapyd.net/t/unable-to-verify-webhook-signature-on-node-js/58836/1 "2023-08-21T09:26:57Z")

</div>

Hello,

I am trying to verify the webhook signature and I cannot get it working. I am following [https://docs.rapyd.net/en/webhook-authentication.html](https://this) guide, but the calculated signature is different from the signature sent.

```auto
import { createHmac } from 'crypto';

// the request object is an express request object
const bodyString = request.rawBody ? request.rawBody.toString('utf8') : '';
const salt = request.get('salt');
const signature = request.get('signature');
const timestamp = request.get('timestamp');
const url = request.protocol + '://' + request.get('host') + request.originalUrl;
const accessKey = process.env.RAPYD_ACCESS_KEY;
const secretKey = process.env.RAPYD_SECRET_KEY;
const data = `${url}${salt}${timestamp}${accessKey}${secretKey}${bodyString !== '{}' : bodyString : ''}`;
let hash;
let calculatedSignature;

try {
  hash = createHmac('sha256', secretKey);
  hash.update(data);

  calculatedSignature = Buffer.from(hash.digest('hex')).toString('base64');
} catch (error) {
  console.error(error);

  throw new Error('InternalServerError');
}

if (calculatedSignature !== signature) {
  throw new Error('Unauthorized');
}

```

Related, but unresolved posts:

- [Unable to verify webhook signature (NodeJS)](https://community.rapyd.net/t/unable-to-verify-webhook-signature-nodejs/57524)

---

<div class="post-metadata">

**Author:** ![nettle\_kieran](https://sea2.discourse-cdn.com/flex016/user_avatar/community.rapyd.net/nettle_kieran/32/22076_2.png) [@nettle\_kieran](https://community.rapyd.net/u/nettle_kieran)\
**Post date:** [August 21, 2023, 9:41am UTC](https://community.rapyd.net/t/unable-to-verify-webhook-signature-on-node-js/58836/2 "2023-08-21T09:41:26Z")

</div>

My bad on this one.

Silly mistake. I was using ngrok to tunnel the webhook to my local machine and `request.protocol` is returning ‘http’, but the tunnel is using ‘https’.

Everything works when I explicitly set the webhook URL to the full URL that I set when defining the webhook.

Note: this is the full URL, NOT the path, i.e. [https://youdomain.com/rapyd-webhook-endpoint](https://youdomain.com/rapyd-webhook-endpoint)
