Skip to main content

One post tagged with "api"

View All Tags

Check the token or trust the call: verifying signature webhooks

· 4 min read
Julien Jenoudet
CEO of IgniSign

Your product has a new flow: a user signs a mandate inside your app, and the moment the signature is done your backend activates the account, releases the file or moves the deal forward. That moment arrives as a webhook. The decision every integrating developer faces is simple to state: does your handler act on any call that reaches the endpoint, or does it first confirm that the call really came from IgniSign?