Skip to content

Add webhook signature verification and typed event models - #10

Merged
SlimAhmad merged 1 commit into
mainfrom
feature/webhook-verification-and-events
Sep 16, 2026
Merged

SlimAhmad merged 1 commit into
mainfrom
feature/webhook-verification-and-events

Conversation

@SlimAhmad

Copy link
Copy Markdown
Owner

Summary

FlutterWave's webhooks are inbound — the merchant hosts an endpoint and Flutterwave POSTs event payloads to it — so this SDK (which only wraps outgoing API calls) can't "listen" for them itself. This adds the two pieces it can usefully provide for that flow:

  • FlutterWave.Core.Webhooks.WebhookSignatureVerifier — constant-time comparison of the verif-hash header against your configured secret hash, per the docs' "Verifying Webhook Signatures" section.
  • FlutterWave.Core.Webhooks.Events — typed payload models for every event type shown in the docs (charge.completed, transfer.completed covering successful/failed transfer + wallet funding + PSA inflow, subscription.cancelled, bvn.completed, singlebillpayment.status), plus the un-enveloped virtual card debit/OTP and refund payloads, via a generic WebhookEvent<TData> envelope where the payload has an event/data wrapper.

Test plan

  • dotnet build FlutterWave.Core.sln — 0 warnings, 0 errors
  • dotnet test FlutterWave.Core.Tests.Unit — 1296/1296 passing, including 18 new tests: verifier match/mismatch/null-or-empty cases, and deserialization of each event type's actual sample payload from the docs

🤖 Generated with Claude Code

FlutterWave webhooks (https://developer.flutterwave.com/docs/webhooks)
are inbound: the merchant hosts an endpoint and Flutterwave POSTs event
payloads to it. This library only wrapped outgoing API calls, so add the
two pieces an SDK can usefully provide for that flow without needing a
server/controller layer of its own:

- WebhookSignatureVerifier: constant-time comparison of the `verif-hash`
  header against the merchant's configured secret hash, per the docs'
  "Verifying Webhook Signatures" guidance.
- Typed payload models under FlutterWave.Core.Webhooks(.Events) for every
  event shown in the docs (charge.completed, transfer.completed incl.
  wallet funding/PSA inflow, subscription.cancelled, bvn.completed,
  singlebillpayment.status, plus the un-enveloped virtual card debit/OTP
  and refund payloads), via a generic WebhookEvent<TData> envelope where
  the payload has one.

Unit tests cover the verifier's match/mismatch/null-or-empty cases and
deserialize each event's actual sample payload from the docs.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@SlimAhmad
SlimAhmad merged commit db9cbee into main Sep 16, 2026
1 check failed
@SlimAhmad
SlimAhmad deleted the feature/webhook-verification-and-events branch September 16, 2026 23:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant