{"uid":"cap_Omiy9pUXHsNyrykkn9qfE","slug":"delx-commerce-webhook-signature-timestamp-check-8dff0ccc","name":"Delx Commerce — Webhook Signature Timestamp Check","description":"Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.","url":"https://commerce.delx.ai/api/v1/x402/webhook-signature-timestamp-check?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"now_epoch":{"type":"integer","description":"Now Epoch supplied to Webhook Signature Timestamp Check; used only for this bounded calculation and processed in memory without retention."},"timestamp_epoch":{"type":"integer","description":"Timestamp Epoch supplied to Webhook Signature Timestamp Check; used only for this bounded calculation and processed in memory without retention."},"maximum_age_seconds":{"type":"integer","description":"Maximum Age Seconds supplied to Webhook Signature Timestamp Check; used only for this bounded calculation and processed in memory without retention."},"maximum_future_skew_seconds":{"type":"integer","description":"Maximum Future Skew Seconds supplied to Webhook Signature Timestamp Check; used only for this bounded calculation and processed in memory without retention."}}},"responseSchema":{"type":"json","example":{"result":{"age_seconds":120,"within_window":true,"signature_verified":false},"schema":"delx/util-webhook-signature-timestamp-check/v1","status":"pass","evidence":{"retained":false,"input_sha256":"399247a496498846768188f051c797a1de4857867f694fadcc7a0037c29feb35","external_calls":0},"operation":"web_reliability:webhook_signature_timestamp_check"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_Ww7GWIsN1Vfv8HxvY98mT","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Validates whether a webhook signature timestamp falls within an acceptable age and future-skew window, returning pass/fail with computed age in seconds.","exampleAgentPrompt":"Check whether a webhook timestamp of 1717000000 is still valid right now (current time 1717000120), using a maximum age of 300 seconds and a maximum future skew of 30 seconds.","exampleUseCases":[{"title":"Replay attack prevention for webhooks","prompt":"I just received a webhook with a signature timestamp of 1717000000 and the current time is 1717000120. Check if it's within a 5-minute max age and 60-second future skew window so I know it's not a replay attack."},{"title":"Webhook freshness check before processing","prompt":"Before I process this incoming webhook, verify its timestamp — the webhook timestamp is 1716999800, now is 1717000000, max age allowed is 180 seconds, and max future skew is 30 seconds. Is it fresh enough?"},{"title":"Automated webhook validation in agent pipeline","prompt":"My agent pipeline received a webhook at epoch 1717005000 and the current epoch is 1717005050. Validate the timestamp with a 120-second max age and 10-second future skew limit so I can decide whether to accept or reject it."}],"resultDescription":"Returns a JSON object containing the computed age_seconds between the two timestamps, a within_window boolean indicating whether the timestamp is acceptable, a signature_verified boolean, an overall status of 'pass' or 'fail', and an evidence object with a SHA-256 hash of the input and confirmation that no data was retained and no external calls were made.","failureModes":["Missing required fields (now_epoch, timestamp_epoch, maximum_age_seconds, maximum_future_skew_seconds) result in validation error","Non-integer epoch values cause schema rejection","Timestamp too old — age_seconds exceeds maximum_age_seconds, within_window returns false, status fails","Timestamp too far in the future — exceeds maximum_future_skew_seconds, within_window returns false","Payment failure via x402 protocol blocks the call entirely"],"whenToPreferThis":"Choose this endpoint when you need a lightweight, pay-per-call, no-signup webhook timestamp validator with cryptographic evidence of computation (SHA-256 input hash) and explicit confirmation of no data retention. It is ideal for agent pipelines that need to programmatically verify webhook freshness and replay-attack windows without standing up their own time-window logic, and where verifiable, auditable delivery via USDC micropayment is preferred over a subscription API.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T04:57:43.753Z","isFirstParty":false,"canonicalSlug":"delx-commerce-webhook-signature-timestamp-check-8dff0ccc"}