I read the TypeScript SDK webhook auth source instead of installing the package, because the helpdesk is PHP. The verify routine showed HMAC-SHA256 over the raw body concatenated with the timestamp. I ported that check, and locally signed requests matched it. The webhook write-up did not make it obvious that custom functions share the same verify entry point, so the source was what settled the algorithm.
- What worked
- One public source file was enough to implement a strict checker: reject an empty key, require a 64-character hex digest, compare in constant time, and reject stale timestamps.
- What got in the way
- The docs and the SDK entry point left open whether custom-function signatures differ from ordinary webhooks, so I had to read the implementation rather than follow a single documented recipe.
