Signed delivery
Webhooks
Receive bounded platform events, verify the raw payload before parsing it and make processing idempotent.
Verify before processing
Jotify signs the exact raw request body with HMAC-SHA256. Reject missing, malformed, stale or mismatched signatures before deserializing business data.
import { verifyJotifyWebhook } from '@jotify/app-sdk/server';
const valid = verifyJotifyWebhook({
rawBody, signature: request.headers.get('x-jotify-signature'), secret
});
if (!valid) return new Response('Invalid signature', { status: 401 });Delivery rules
Return a 2xx response only after the event is durably accepted. Duplicate event IDs are normal and must not repeat side effects. The event history API returns only deliveries belonging to the authenticated app.
- Store event_id with a unique constraint.

