Skip to content

webhook_signature_invalid

POST /stripe/webhook could not verify the Stripe-Signature header against the configured signing secret - unsigned, wrongly signed, or outside the 300-second replay tolerance. 400 rather than 401 because there is no credential to re-present. A deployment with no signing secret refuses every webhook rather than trusting one.

Problem shape

Every non-2xx response is an RFC 9457 application/problem+json body. The type URI below is stable and machine-matchable, so branch on the final path segment (the code) and treat the status as redundant confirmation. See the error-handling guide.

{
  "type": "https://docs.vocapable.com/errors/webhook_signature_invalid",
  "title": "…",
  "status": 400,
  "detail": "…",
  "instance": "/v1/…"
}

← Back to the error registry