Skip to content
1 minute readAPIAgent-ready

Webhooks are signed under x-lastprice-signature

Every webhook now carries its signature in x-lastprice-signature and its timestamp in x-lastprice-timestamp. The previous signature and timestamp headers are still sent with the same values.

The webhooks section of the API documentation in dark mode naming the x-lastprice-signature and x-lastprice-timestamp headers

Webhook deliveries now name their signature after Last Price.

  • Each delivery and each test event from the dashboard carries x-lastprice-signature (HMAC-SHA256 of the raw body, hex) and x-lastprice-timestamp (Unix seconds).
  • The previous signature and timestamp headers are still sent with the same values, so a receiver built against them keeps working with no change.
  • To move over, read x-lastprice-signature instead of the previous header. The value and how you check it are the same.