cancel
Showing results for 
Search instead for 
Did you mean: 

WAF doesn't support dynamic signatures

InfoSecSupport
Newcomer
Newcomer

Reviewing your documentation on webhooks at the link below.

https://developers.zoom.us/docs/api/webhooks/#verify-webhook-events

Our WAF cannot support a dynamic style signature verification as requested per the docs (copy and pasted below).

"To verify that Zoom sent a webhook request, use the webhook secret token and the webhook request body to create a signature to compare with the x-zm-signature header value sent by Zoom."

Is there a way to set a static value we could check against?

Thank you

0 REPLIES 0