Skip to main content
Verify webhook signatures to ensure payloads from Cashfree haven’t been tampered with. This security measure prevents fraudulent notifications and protects your application from malicious attacks. Essential for production environments: all merchants processing live payments, subscriptions, or marketplace transactions must implement signature verification to maintain security and prevent financial losses.
Cashfree generates the webhook signature based on the raw payload, not the parsed payload. For an example of accessing the raw body in a JavaScript framework, see the NestJS raw-body documentation. Even minor changes to the payload structure or parameter sequence result in a signature mismatch. Use the exact raw webhook body as received at your server, without parsing, re-serialisation, formatting, or modification.
Use the signature to verify that the request hasn’t been tampered with. You need your Cashfree PG secret key and the payload to verify the signature.
For partner webhooks, use the partner API key.
  • The timestamp is present in the header x-webhook-timestamp.
  • The actual signature is present in the header x-webhook-signature.
signature-verification
Cashfree recommends verifying webhook signatures to protect against payload manipulation. You can use the Webhook Verification tool in Dev Studio to manually verify whether a payload and signature are valid before implementing verification in your code.

SDK verification (built-in approach)

Manual verification (custom approach)