Verifying Webhook Authenticity
Webhook requests sent from Lendflow include HTTP headers that can be used to verify the request actually came from Lendflow and that the request body was not modified while in transit.Lendflow-Verification-Signature— the signature to validate againstLendflow-Verification-Timestamp— a timestamp value
Verifying a Signature
Signature verification is done within your application’s code by attempting to recreate and match the signature sent in theLendflow-Verification-Signature header. The process in pseudocode is as follows:
Bash
The Webhook SecretVerification signatures are signed by your organization’s webhook secret; a token that should be viewed and treated like a password.
Your organization’s webhook secret must be requested from Lendflow’s customer success team.
Code Examples
PHP
webhook.php
Javascript
FAQ
Is webhook verification required?
Is webhook verification required?
No. Webhook verification is optional, but recommended. It confirms the request came from Lendflow and that the body was not modified in transit.
Where do I get the webhook secret?
Where do I get the webhook secret?
Verification signatures are signed by your organization’s webhook secret. Treat that token like a password. Request it from Lendflow’s customer success team.
Why does signature verification fail?
Why does signature verification fail?
Recreate the signature as
base64encode(hmac('sha256', timestamp + body, webhook_secret)) and match it to Lendflow-Verification-Signature. If even a single character in the body changes before you hash it, including how escape characters are handled, verification fails. Reject the request when the signatures do not match.Next steps
Custom Workflows Webhooks
Choose which workflow events send webhooks and where they are delivered.
Submit A New Application Via The API
Authenticate, set workflow_template_id, and submit a deal payload.