product image

Webhook Signature Verification — FastAPI

$9

Correct Whop webhook verification — HMAC, idempotent, tested.

FastAPI microservice for receiving Whop webhooks: HMAC-SHA256 signature verification (constant-time), 300s anti-replay window, and idempotency via Redis so retried deliveries never double-process a payment.

Why this exists: as of writing, Whop’s own docs say the official verification helper ‘lands in the next release’ — it’s not published yet. This implements exactly what Whop’s own documentation recommends as the interim approach, not a guessed workaround.

What you get:

  • Full FastAPI service, ready to deploy
  • 5/5 tests: correct signature, forged signature, expired timestamp, tampered body, key-rotation multi-signature
  • Redis-based idempotency (SET NX, atomic)

Data Quality Disclosure: the exact key-derivation for WHOP_WEBHOOK_SECRET follows the Standard Webhooks (Svix) convention Whop says it implements, but hasn’t been confirmed against a real Whop webhook delivery. Safe failure mode: if wrong, it rejects valid signatures — it never accepts a forged one.

Python. Delivered as ZIP with requirements.txt.