Every outgoing webhook payload sent by Playground API includes a cryptographic signature in the X-Playground-Signature header. Verify signatures in your receiver to authenticate origin, prevent payload tampering, and defend against replay attacks.
Select an event topic to inspect the raw JSON payload and the corresponding cryptographic signature headers:
The Playground API includes the following HTTP request headers on every outgoing webhook dispatch:
| Header | Sample Value | Purpose & Description |
|---|---|---|
| X-Playground-Signature | t=1759165200,v1=9a2b8... | Cryptographic HMAC-SHA256 signature to verify payload authenticity. |
| X-Playground-Event | posts.created | Domain event name allowing consumers to filter or route payloads. |
| X-Playground-Delivery | del_4a9e21... | Unique transmission UUID for receiver idempotency and de-duplication. |
| User-Agent | Playground-API-Webhook-Dispatcher/1.0 | Standard User-Agent identifier sent by the dispatcher client. |
Production signature verification implementations in Node.js, Python, or Go:
Never use standard string equality (== or ===). Always use constant-time functions like Node's crypto.timingSafeEqual or Python's hmac.compare_digest.
Verify that the timestamp t in the header is within 300 seconds (5 minutes) of current server time to reject stale intercepted requests.
Do not parse the body to an object and re-stringify it. Key ordering differences will break HMAC verification. Compute HMAC directly over the raw incoming request buffer.
Store X-Playground-Delivery in Redis or a DB unique index. Acknowledge duplicates with HTTP 200 immediately without reprocessing business actions.