Skip to main content
Every webhook Pagoramp sends to your configured webhookUrl is signed with your account’s webhook secret. Verifying the signature confirms the request actually came from Pagoramp and wasn’t forged or replayed.

Headers

Each webhook request includes two headers:
  • X-Pagoramp-Signature: a hex-encoded HMAC-SHA256 signature of the request.
  • X-Pagoramp-Timestamp: the Unix timestamp (seconds) the request was signed at.

Getting your webhook secret

Generate or view your webhook secret in the merchant dashboard under Settings > Webhooks. It’s shown once at generation time - store it securely. You can regenerate it at any time (this invalidates the previous secret).

Signature construction

raw_request_body is the exact, unparsed JSON body of the request - verify against the raw bytes, not a re-serialized version of the parsed object (re-serializing can change key ordering or whitespace and break the signature).

Verifying (Node.js example)