IntegrationIntermediatewebhooksecurityhmac
Design webhook HMAC signature verification for inbound Salesforce integrations
Real World Scenario
Public REST endpoint receives purported Salesforce webhooks; attacker forged payload creates fraudulent refund records.
Expected Answer
• HMAC-SHA256 signature in X-Signature header shared secret or cert
• Verify signature before parsing body or DML
• Timestamp tolerance 5 minutes preventing replay attacks
• Constant-time signature comparison preventing timing attacks
• Rotate webhook secrets via Named Credential update
• Reject unsigned requests no fallback processing
• Log verification failures security monitoring
Follow-Up Questions & Answers
Click to expand — each follow-up includes a direct, interview-ready answer
Direct answer: HMAC-SHA256 signature in X-Signature header shared secret or cert Also consider: Verify signature before parsing body or DML In practice: Timestamp tolerance 5 minutes preventing replay attacks Balance speed of delivery with maintainability.
Architect Perspective
Inbound webhooks are attack surface—verify authenticity before any Salesforce write.