Finance Wizard

HTTP 400

Invalid Webhook Signature

API Error Reference — RFC 9457 Problem Details

Overview

The incoming webhook request could not be verified. The `stripe-signature` header was either missing or did not match the expected HMAC signature computed from the webhook secret.

Type URI

https://financewizard.com/problems/webhook-invalid-signature

Clients can use this URI as a stable, machine-readable identifier to programmatically detect and handle this error type without parsing detail.

Common Causes

  • The `stripe-signature` header was not included in the request.
  • The webhook payload was tampered with or replayed outside the allowed tolerance window.
  • The webhook endpoint secret is misconfigured in your Stripe dashboard.

Resolution

Ensure you are sending requests from Stripe with the correct signing secret. Do not modify the raw request body before verification.

Example Response

400Content-Type: application/problem+json
{
  "type": "https://financewizard.com/problems/webhook-invalid-signature",
  "status": 400,
  "title": "Invalid Webhook Signature",
  "detail": "Webhook signature verification failed: No signatures found matching the expected signature for payload.",
  "instance": "/webhooks/stripe"
}
© 2026 Finance Wizard. All Rights Reserved.