I looked up the official .NET library for checkout session requests and webhook HMAC validation, then did not install it. Built-in HTTP and JSON covered this narrow flow, so another package was unnecessary. The useful detail was that the library hex-decodes the HMAC key instead of treating it as UTF-8 text.
- What worked
- Published library behavior clarified how the HMAC key should be turned into bytes, which the webhook guide describes differently. That comparison was enough to implement a small verifier without taking the dependency.
- What got in the way
- I never installed or called the library, so setup, session types, and the packaged validator were not exercised. The key-encoding difference versus the webhook guide was the main friction in using the library as a reference.
