Signatures Added to Dispatch Webhook Notifications

Leap now signs dispatch event notifications sent to your webhook endpoint. Each notification includes an x-leap-signature header containing a timestamped HMAC-SHA256 signature. Verifying it confirms three things: the notification came from Leap, the payload wasn't modified in transit, and an old notification isn't being replayed. This applies to both meter-level and group-level dispatch webhooks.

When you create a webhook with the set meter webhook URL or set group webhook URL endpoint, the response now includes a signing_secret. Each webhook has its own secret. Store it securely because Leap only returns it once and can't show it again. See step 2 of the Dispatch Webhooks guide for details on the signing secret. See step 4 for how to verify signatures, including a test vector for checking your implementation.

  • Existing webhooks: Webhooks created before signing was introduced don't have a secret. Their notifications are sent without the x-leap-signature header. To start receiving signed notifications, update your webhook with rotate_secret=true to generate a secret. Remember to include any custom headers if you also want these sent with the notifications.
  • Rotating secrets: Updating a webhook with rotate_secret=true generates a new secret, which replaces the old one immediately. To avoid failed verifications during the switch, you can accept both the old and new secret for a short time. You can also rely on Leap's retries, which are re-signed and continue for up to 50 minutes.
  • Testing: Notifications sent with the trigger test notification endpoints are signed the same way as real dispatch notifications. Use them to validate your implementation before going live.

Signature verification is now the recommended way to authenticate notifications from Leap. Custom headers in the headers array are still supported and can be used alongside it, for example to reject requests earlier at your API gateway.