Webhooks: signature with your account secret
New webhook signature (action required by 2026-10-29)
Callbacks sent to thecallbackUrl of charges and payouts now carry two new headers:X-Safefy-Timestamp: send time, in Unix seconds.X-Safefy-Signature-V2:t={timestamp},v1={HMAC-SHA256(secret, "{timestamp}.{body}")}.
X-Safefy-Signature) used the payment or payout ID as the key, and the
payer knows that ID. With the account secret, only Safefy can sign a valid callback. The timestamp in the signature
blocks replays of old callbacks.What to do:- Get the secret from the dashboard and store it on your server.
- Validate
X-Safefy-Signature-V2over the raw request body. - Reject callbacks with an invalid signature or older than 5 minutes.
- When in doubt, confirm the status through the API before releasing the order.
X-Safefy-Signature header stops being sent on 2026-10-29. Until then both are sent.Step by step and examples in Node.js, Python, PHP and C#: Webhooks → Signature.Dashboard: production API credentials need a code