Skip to main content
GET

Authentication

This endpoint requires a Bearer token in the Authorization header.

Response

string
The ED25519 public key in base64 encoding. Use this key to verify the X-Signature header on incoming webhook requests.
string
The signature algorithm used. Always ED25519.

Signature Verification

Each webhook request includes an X-Signature header containing an ED25519 signature of the raw request body. To verify:
  1. Retrieve the public key from this endpoint (cache it, as it rarely changes).
  2. Read the raw request body bytes from the incoming webhook.
  3. Verify the X-Signature header value against the body using the ED25519 public key.
Node.js Example