For the complete documentation index, see llms.txt. This page is also available as Markdown.

Why does my webhook signature verification fail?

Signature failures almost always mean the signing secret used for verification does not match the one Terra signed with, not a change on Terra's side.

Signature failures almost always mean the signing secret used for verification does not match the one Terra signed with, not a change on Terra's side.

Each environment and each webhook has its own secret, so using a production secret in staging (or vice versa) yields no matching signature. A common pattern: multiple dev_ids (production, staging, testing) each have their own secret but all point at the same destination URL, so a verifier holding one secret rejects events signed by the others.

To fix it:

1

Find the correct secret in the dashboard: open the three-dots menu on the webhook, then Edit.

2

Either give each dev_id its own webhook URL/destination, or disable destinations on unused environments.

3

Upgrade to the latest SDK, which deprecates the legacy secret_key flow.

Last updated

Was this helpful?