{"uid":"cap_xgjxiuFmsohj-YcOpkb1s","slug":"webhook-verifier-19174f75","name":"Webhook Verifier","description":"Validate declared signature status, freshness and payload evidence","url":"https://phion.systems/v1/paid/trust/webhook-verifier","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema"},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_OJGSgEv2JgH_Rap1kP0M6","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Validates the signature status, freshness, and payload evidence of incoming webhooks to confirm authenticity and integrity","exampleAgentPrompt":"Before I process this incoming webhook event, verify that its declared signature is valid, the timestamp is fresh, and the payload evidence checks out — I don't want to act on a forged or replayed message.","exampleUseCases":[{"title":"Guard payment event processor","prompt":"I just received a payment webhook from our payment provider — before I update any order status, can you verify its signature is legitimate, it's not a replay, and the payload evidence is intact?"},{"title":"Validate CI/CD pipeline trigger","prompt":"A webhook just came in claiming to be a GitHub push event triggering our deployment pipeline — verify the declared signature and freshness before I let it kick off anything."},{"title":"Secure agentic tool callback","prompt":"My agent just received a callback webhook from an external tool — check the signature status and confirm the payload evidence is valid and the timestamp is recent enough before I trust it."}],"resultDescription":"Returns a structured assessment of the webhook's declared signature status (valid/invalid), freshness evaluation (to detect stale or replayed payloads), and payload evidence integrity — yielding an overall trust verdict indicating whether the webhook is safe to act upon.","failureModes":["Missing or malformed signature field causes validation failure","Timestamp outside acceptable freshness window triggers replay-attack rejection","Payload evidence mismatch indicates tampering or corruption","Empty or schema-invalid request body returns an error","Unrecognized signature algorithm may result in undetermined status"],"whenToPreferThis":"Use this endpoint when an agent needs to verify the authenticity, freshness, and payload integrity of an incoming webhook before taking any downstream action — particularly in agentic pipelines where acting on forged or replayed events could cause financial, security, or data integrity harm. It is especially suited for x402 payment events, tool callbacks, and any event-driven triggers where trust must be explicitly established before execution.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T06:50:28.027Z","isFirstParty":false}