Secret Key
Your webhook secret is available in the Advanced tab of your account settings. Each account has a unique secret used to sign all webhook requests.Signature Verification
Each webhook request includes anX-Firecrawl-Signature header:
How to Verify
- Extract the signature from the
X-Firecrawl-Signatureheader - Get the raw request body (before parsing)
- Compute HMAC-SHA256 using your secret key
- Compare signatures using a timing-safe function
Implementation
Best Practices
Always Verify Signatures
Never process a webhook without verifying its signature first:Use Timing-Safe Comparisons
Standard string comparison can leak timing information. Usecrypto.timingSafeEqual() in Node.js or hmac.compare_digest() in Python.
