Zoom Contact Center Webhook 403 Forbidden on /webhooks/events

Getting a 403 Forbidden whenever the webhook tries to push events to our listener. Zoom Contact Center SDKs usually require a strict handshake for validation, but the architectural failure is happening before the payload even hits the logic.

@zoomus/contact-center-sdk is returning the error during the verification phase. Tried updating the secret in the portal and rotating the endpoint URL, but the response stays the same.

const signature = crypto.createHmac('sha256', secret).update(payload).digest('hex');
``` Is the listener comparing the `X-Zoom-Signature` header against a raw body string or a parsed JSON object? If it's parsed, the hash won't match and the SDK'll throw that 403 during the verification phase.
1 Like