Salesforce Decode
Salesforcedecode
Back to questions
IntegrationIntermediatewebhooksecurityhmac

Design webhook HMAC signature verification for inbound Salesforce integrations

Real World Scenario

Public REST endpoint receives purported Salesforce webhooks; attacker forged payload creates fraudulent refund records.

Expected Answer

• HMAC-SHA256 signature in X-Signature header shared secret or cert • Verify signature before parsing body or DML • Timestamp tolerance 5 minutes preventing replay attacks • Constant-time signature comparison preventing timing attacks • Rotate webhook secrets via Named Credential update • Reject unsigned requests no fallback processing • Log verification failures security monitoring

Follow-Up Questions & Answers

Click to expand — each follow-up includes a direct, interview-ready answer

Direct answer: HMAC-SHA256 signature in X-Signature header shared secret or cert Also consider: Verify signature before parsing body or DML In practice: Timestamp tolerance 5 minutes preventing replay attacks Balance speed of delivery with maintainability.

Architect Perspective

Inbound webhooks are attack surface—verify authenticity before any Salesforce write.