Skip to main content

api-webhooks-hono

@rtorcato/api-webhooks-hono is the Hono adapter for api-webhooks. It verifies the HMAC signature over the raw request body.

Install

pnpm add @rtorcato/api-webhooks @rtorcato/api-webhooks-hono hono

hono is a peer dependency (^4) — you bring your own version.

Usage

import { webhookMiddleware } from '@rtorcato/api-webhooks-hono'

// GitHub-style webhook: header `x-hub-signature-256: sha256=<hmac>`
app.post('/webhooks/github', webhookMiddleware({
secret: env.WEBHOOK_SECRET,
header: 'x-hub-signature-256',
prefix: 'sha256=',
}), async (c) => {
const payload = await c.req.json() // body is buffered; safe to read here
return c.body(null, 204)
})

On a missing/invalid signature it responds 401 with the standard error envelope from api-errors. Hono buffers the request body, so the downstream handler can still call c.req.json() after the middleware reads it as text.