Setting up an Express endpoint to catch webhook events for case workflow interactions. Trying to verify the signature header before processing payloads to stop replay attacks. The platform docs mention HMAC-SHA256 with the client secret, but the hash never matches.
const crypto = require('crypto');
const sig = req.headers['x-genesys-cloud-signature'];
const ts = req.headers['x-genesys-cloud-timestamp'];
const raw = JSON.stringify(req.body);
const expected = crypto.createHmac('sha256', process.env.GENESYS_SECRET)
.update(`${ts}.${raw}`)
.digest('hex');
It’s failing on every request. We’ve double-checked the secret in the integration settings. Maybe the payload needs to be raw instead of parsed JSON? Express body-parser might be mucking with the stringification order. The timestamp window can’t be that tight for Tokyo to US-East latency. Anyone got a working verification snippet for Express? Logs show the events hitting the queue but the signature check kills the callback every time. Not sure why the HMAC keeps drifting.