hooksig

hooksig  /  DocuSign

HMAC-SHA256 · base64 · no timestamp

DocuSign

DocuSign Connect signs like Shopify, base64 over the raw body, and rotates keys across numbered headers.

Try it, live in your browser

HMAC-SHA256 · base64 · no timestamp
Request: edit anything
Verify this in code
import { verify } from "hooksig";

const result = await verify("docusign", {
  payload: rawBody,            // the RAW body, not parsed JSON
  headers: request.headers,
  secret: env.WEBHOOK_SECRET,
});

if (!result.verified) {
  return new Response(result.reason, { status: 400 });
}
no match: signature invalid
Signed string
HMAC-SHA256( secret, signed string ) = expected
Expected vs provided
expected
provided
How it's built

    The scheme

    Gotchas

    Official DocuSign docs →