# Webhook Signature validation fails

**URL:** <https://www.patreondevelopers.com/t/webhook-signature-validation-fails/348>\
**Category:** API Feedback\
**Created:** [March 14, 2018, 11:03pm UTC](https://www.patreondevelopers.com/t/webhook-signature-validation-fails/348 "2018-03-14T23:03:12Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![sam](https://yyz2.discourse-cdn.com/flex036/user_avatar/www.patreondevelopers.com/sam/32/492_2.png) [@sam](https://www.patreondevelopers.com/u/sam)\
**Post date:** [March 19, 2018, 9:08pm UTC](https://www.patreondevelopers.com/t/webhook-signature-validation-fails/348/4 "2018-03-19T21:08:24Z")

</div>

Are you using the body-parser for Express 4, configured to parse JSON POST requests? i.e:

```
const bodyParser = require('body-parser')
app.use(bodyParser.json());

```

Without that Express won’t parse the body of the POST request – which will result in the signature validation failing. The code you’ve provided works for me, too, when `body-parser` is included with the `json` parser chosen. you can try it here:

> **[Glitch](https://glitch.com/edit/#!/patreon-signature)**
>
> Combining automated deployment, instant hosting & collaborative editing, Glitch gets you straight to coding so you can build full-stack web apps, fast

```
const express = require('express')
const app = express()
const crypto = require('crypto')
const bodyParser = require('body-parser')

app.use(bodyParser.text({type: '*/*'}));

app.post("/webhook", (request, response) => {
  const webhookSecret = 'secret';
  
  let hash = crypto.createHmac('md5', webhookSecret).update(request.body).digest('hex');
  let success = (request.header('x-patreon-signature') === hash);
  
  console.log('Signature received: ' + request.header('x-patreon-signature'));
  console.log('Signature generated: ' + hash);
  console.log('Signature validation status: ' + success);
    
  return response.status(success ? 200 : 400).json({result: success});
})

app.listen(process.env.PORT)

```

Edit: this code was updated on May 31st, 2018, to fix a bug: parsing the input as JSON and then turning it back into a string can cause some encoding issues which will cause signature verification to fail _sometimes_.

---

_[View the full topic](https://www.patreondevelopers.com/t/webhook-signature-validation-fails/348)._
