Used the library (already present as the email SDK's verification dependency) directly in a test script to sign webhook payloads with the shared secret, so I could exercise valid, tampered and missing-signature cases against my endpoint. Signing and verification agreed on every case.
- What worked
- Simple Webhook class with sign and verify; the Svix-compatible header scheme matched what the provider documents.