Verify the signature before you parse the JSON body. Pass the unmodified request bytes to the SDK.
import { AffinityWebhookVerificationError, verifyAffinityWebhook } from "@affinity-health/sdk";
export async function handleAffinityWebhook(request: Request) {
try {
const event = await verifyAffinityWebhook({
body: await request.arrayBuffer(),
secret: process.env.AFFINITY_WEBHOOK_SECRET!,
signature: request.headers.get("affinity-signature"),
});
await saveEvent(event);
return new Response(null, { status: 204 });
} catch (error) {
if (error instanceof AffinityWebhookVerificationError) {
return Response.json({ error: error.code }, { status: 400 });
}
throw error;
}
}The SDK checks the timestamp and HMAC-SHA256 digest. Store each event ID before you apply its state change.
Read the webhook guide to configure endpoints, subscriptions, retries, and replay.