Why does my webhook signature verification fail?
Signature failures almost always mean the signing secret used for verification does not match the one Terra signed with, not a change on Terra's side.
Signature failures almost always mean the signing secret used for verification does not match the one Terra signed with, not a change on Terra's side.
Each environment and each webhook has its own secret, so using a production secret in staging (or vice versa) yields no matching signature. A common pattern: multiple dev_ids (production, staging, testing) each have their own secret but all point at the same destination URL, so a verifier holding one secret rejects events signed by the others.
To fix it:
Find the correct secret in the dashboard: open the three-dots menu on the webhook, then Edit.
Either give each dev_id its own webhook URL/destination, or disable destinations on unused environments.
Upgrade to the latest SDK, which deprecates the legacy secret_key flow.
Last updated
Was this helpful?