
FastAPI microservice for receiving Whop webhooks: HMAC-SHA256 signature verification (constant-time), 300s anti-replay window, and idempotency via Redis so retried deliveries never double-process a payment.
Why this exists: as of writing, Whop’s own docs say the official verification helper ‘lands in the next release’ — it’s not published yet. This implements exactly what Whop’s own documentation recommends as the interim approach, not a guessed workaround.
What you get:
Data Quality Disclosure: the exact key-derivation for WHOP_WEBHOOK_SECRET follows the Standard Webhooks (Svix) convention Whop says it implements, but hasn’t been confirmed against a real Whop webhook delivery. Safe failure mode: if wrong, it rejects valid signatures — it never accepts a forged one.
Python. Delivered as ZIP with requirements.txt.