# Verify Webhook Signature?

**URL:** <https://community.rapyd.net/t/verify-webhook-signature/1383>\
**Category:** 🌱 Payments 101\
**Created:** [January 14, 2022, 10:55am UTC](https://community.rapyd.net/t/verify-webhook-signature/1383 "2022-01-14T10:55:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Minh\_Nguy\_n\_Van](https://sea2.discourse-cdn.com/flex016/user_avatar/community.rapyd.net/minh_nguy_n_van/32/1424_2.png) [@Minh\_Nguy\_n\_Van](https://community.rapyd.net/u/Minh_Nguy_n_Van)\
**Post date:** [January 14, 2022, 10:55am UTC](https://community.rapyd.net/t/verify-webhook-signature/1383/1 "2022-01-14T10:55:58Z")

</div>

Hello everyone!

I have a question related Rapyd webhook. I want to verify the signature get from webhook. I am PHP Developer and this is my code:

```auto
<?php
$access_key = 'access-key'; // get from Dashboard
$secret_key = 'secret-key'; // get from Dashboard

$salt = 'epiAT7douEg/9ezxZzoByA=='; // get from webhook header
$timestamp = 1642058448; // get from webhook header
$signature_from_webhook = 'base-64-value'; // get from webhook header

// Data from payment hook https://docs.rapyd.net/build-with-rapyd/reference/payment-object#webhook-payment-completed
$request = json_decode(file_get_contents("php://input"), true); // array value
$body_string = json_encode($body,JSON_UNESCAPED_SLASHES);

// Calulate signature to verify
$sig_string = $path.$salt.$timestamp.$access_key.$secret_key.$body_string;
$hash_sig_string = hash_hmac("sha256", $sig_string, $secret_key);
$my_signature = base64_encode($hash_sig_string);

// Why $my_signature always different from $signature_from_webhook??

?>

```

So, my question is why signature i calulated always different from the webhook?

(I think the $path, $salt, $timestamp, $access\_key, $secret\_key is always right! How about $body\_string format)

Thank you for your reading!

---

<div class="post-metadata">

**Author:** ![Minh\_Nguy\_n\_Van](https://sea2.discourse-cdn.com/flex016/user_avatar/community.rapyd.net/minh_nguy_n_van/32/1424_2.png) [@Minh\_Nguy\_n\_Van](https://community.rapyd.net/u/Minh_Nguy_n_Van)\
**Post date:** [January 14, 2022, 11:00am UTC](https://community.rapyd.net/t/verify-webhook-signature/1383/2 "2022-01-14T11:00:07Z")

</div>

**[Additional Info]** I reference code and docs from:

- Code Sample: [Code Samples](https://docs.rapyd.net/build-with-rapyd/reference/code-samples)
- Webhook Signatures: [Webhooks](https://docs.rapyd.net/build-with-rapyd/reference/webhooks#webhook-signatures)

---

<div class="post-metadata">

**Author:** ![Community\_Team](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@Community\_Team](https://community.rapyd.net/u/Community_Team)\
**Post date:** [January 18, 2022, 7:03pm UTC](https://community.rapyd.net/t/verify-webhook-signature/1383/3 "2022-01-18T19:03:11Z")

</div>

Thanks @Minh_Nguy_n_Van.

This can happen in the $body\_string format as you suspect.

One thing to note, the body should be JSON format, but in the format of a string with no spaces.

For example, if the body is: `{ "hello": "world" }`

It should encoded to a string as: `{"hello":"world"}`

Does this help? You can also complete a ticket at [https://support.rapyd.net](https://support.rapyd.net/) and our support team can help you with all of your sensitive information.
