Skip to content

Document Standard Webhooks signature headers - #69

Open
menewman wants to merge 2 commits into
masterfrom
standard-webhooks-signatures
Open

menewman wants to merge 2 commits into
masterfrom
standard-webhooks-signatures

Conversation

@menewman

@menewman menewman commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Warning

This is a public repo. Keep internal or private context, such as customer names, internal links, or implementation details, out of this PR and its comments. Discuss those in a private channel instead.

Hold: Don't merge until Standard Webhooks signatures are released.

Changes

Updates the webhook docs for the new signature headers:

  • Documents the webhook-id, webhook-timestamp, and webhook-signature headers, with examples for verifying webhook-signature using an official Standard Webhooks library or by hand.
  • Documents the whsec_ secret key format, and that keys in the older format don't receive webhook-signature until they're regenerated.
  • Explains how to switch to a new key without failed deliveries, since the new key takes effect as soon as the webhook is saved.
  • Marks X-CodeSignal-Signature as legacy. It's still sent, so existing integrations keep working.
  • Notes that secret keys can no longer be empty, and lists the new reserved custom header names.
  • Notes that retries keep the same webhook-id and get a new webhook-timestamp.

Both code samples were tested against signatures generated the same way the server generates them.

Testing

You can run the site locally with npm start. Browse the new authentication section in our webhook docs and verify that it matches our updated expectations.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Note

Reviews paused

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: b5b280e4-b7ef-47f6-8faf-e97600ccad20

📥 Commits

Reviewing files that changed from the base of the PR and between 0736a6e and 2aeac3a.

📒 Files selected for processing (1)
  • docs/webhooks/index.html

Included review availability: This review used your included allowance. 1 included review remains after this review. Your included PR review attempts over the past 7 days set your current allowance at 3 reviews per hour.


📝 Walkthrough

Walkthrough

The webhook documentation now describes required secret keys, reserved custom-header names, and Standard Webhooks verification for whsec_ keys. It also documents legacy signature behavior, key format and rotation requirements, and how delivery headers change across retries.

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to 2aeac

The documentation presents consistent verification and key-rotation guidance. No actionable merge-blocking defect was found; publication should remain coordinated with the Standard Webhooks release as requested.

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely describes the main documentation change: adding Standard Webhooks signature headers.
Description check ✅ Passed The description directly explains the webhook documentation updates, key formats, signature verification, migration guidance, and retry behavior.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@menewman

Copy link
Copy Markdown
Member Author

@coderabbitai pause

@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
✅ Action performed

Reviews paused.

@menewman
menewman requested a review from Albinutte September 30, 2026 21:02
@menewman

Copy link
Copy Markdown
Member Author

Requesting review, but it is not urgent (this isn't ready to merge; I'm preparing it in advance)

@Albinutte Albinutte left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update! Approving with a few suggestions 🙏

Comment thread docs/webhooks/index.html
overwrite it with a custom one.
We will generate a <strong>Secret key</strong> automatically. You can replace it
with a custom one, but we recommend keeping the generated key (see
<a href="#authkeyformat">Secret key format</a>).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Probably pre-existing, but it doesn't look great together with the image when the text wraps:

Image

Separately, it would be great to update the screenshots -- they are very outdated 🙈

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'll update the image layout to display it block instead of inline, thanks! I agree with you about the ancient screenshots for sure, but the scope is a little extra so I'm going to leave that out of this PR for now (all of the screenshots are ancient, but the docs overall needs a refresh and I'm not sure I want to get into it in scope of the Standard Webhooks update)

Comment thread docs/webhooks/index.html Outdated
Comment on lines +218 to +219
you've already processed. If several of your webhooks receive the same event,
they all send the same <span class="mono">webhook-id</span>. Treat it as an

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If several of your webhooks receive the same event, they all send the same webhook-id

This sounds a bit confusing to me, but I can't really explain why 😅 Maybe rephrasing it as "If several of your webhooks receive the same event, each of them gets the same webhook-id." will be clearer?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're right. We're saying that webhooks both send and receive events. I think the root confusion is that "webhook" can be used to refer to "the registration that maps some events and headers to a particular handler endpoint" (which is normally how we use it), or it could be used to refer to the handler itself. In this sentence, it's sort of doing both at the same time, and that's strange.

Since our docs generally use meaning 1, I've updated this sentence to be more consistent with that interpretation.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants