{"_id":"@bernierllc/webhook-receiver","_rev":"9-7dc9856dc9996a599db71877da618c89","name":"@bernierllc/webhook-receiver","dist-tags":{"latest":"1.5.0"},"versions":{"1.0.1":{"name":"@bernierllc/webhook-receiver","version":"1.0.1","keywords":["webhook","receiver","http","signature","validation","hmac","jwt","github","stripe"],"author":{"name":"Bernier LLC"},"license":"SEE LICENSE IN LICENSE","_id":"@bernierllc/webhook-receiver@1.0.1","maintainers":[{"name":"alikhan410","email":"mczeyo@gmail.com"},{"name":"mkbernier","email":"mkbernier@gmail.com"}],"homepage":"https://github.com/bernierllc/tools/tree/main/packages/core/webhook-receiver","bugs":{"url":"https://github.com/bernierllc/tools/issues"},"dist":{"shasum":"d8522cac6f6d8f10ee8ee1d6021394173a75276d","tarball":"https://registry.npmjs.org/@bernierllc/webhook-receiver/-/webhook-receiver-1.0.1.tgz","fileCount":35,"integrity":"sha512-v9+weELvm50JgVAHg3pxBDa7ZgkxzgT82ez2prV3zrfXn7KAVFYuTFiCips8vZFEIYgYqrFkmMVOhzwJRl4YmA==","signatures":[{"sig":"MEYCIQChfaylWMTJ8bDPYBDmkSG4NLp1hnWHEfanE8fDKwLDmAIhAJvJbAWP4g+IpHt5H/8nltBdl2SLhDl53w6qWvfaaADA","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":97755},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"84000df3322447045a95956f50048eca3a9da1ba","scripts":{"lint":"eslint src/**/*.ts","test":"echo 'No tests configured'","build":"tsc","clean":"rm -rf dist","test:run":"jest --passWithNoTests","test:watch":"jest --watch","test:coverage":"jest --coverage","prepublishOnly":"npm run clean && npm run build"},"_npmUser":{"name":"mkbernier","email":"mkbernier@gmail.com"},"repository":{"url":"git+https://github.com/bernierllc/tools.git","type":"git","directory":"packages/core/webhook-receiver"},"_npmVersion":"11.4.2","description":"Core HTTP endpoint functionality for receiving and processing webhooks with signature validation","directories":{},"_nodeVersion":"24.4.1","dependencies":{},"publishConfig":{"access":"restricted"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","eslint":"^8.50.0","ts-jest":"^29.1.1","typescript":"^5.2.2","@types/jest":"^29.5.5","@types/node":"^20.6.3","@typescript-eslint/parser":"^6.7.2","@typescript-eslint/eslint-plugin":"^6.7.2"},"_npmOperationalInternal":{"tmp":"tmp/webhook-receiver_1.0.1_1756508639362_0.8434636032091898","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@bernierllc/webhook-receiver","version":"1.2.0","keywords":["webhook","receiver","http","signature","validation","hmac","jwt","github","stripe"],"author":{"name":"Bernier LLC"},"license":"SEE LICENSE IN LICENSE","_id":"@bernierllc/webhook-receiver@1.2.0","maintainers":[{"name":"alikhan410","email":"mczeyo@gmail.com"},{"name":"mkbernier","email":"mkbernier@gmail.com"}],"homepage":"https://github.com/bernierllc/tools/tree/main/packages/core/webhook-receiver","bugs":{"url":"https://github.com/bernierllc/tools/issues"},"dist":{"shasum":"16d03a69b9e8a1104bdb6da0b230fc6253929525","tarball":"https://registry.npmjs.org/@bernierllc/webhook-receiver/-/webhook-receiver-1.2.0.tgz","fileCount":35,"integrity":"sha512-Kl1zaw7xSYh5cEeF0zZ00x8CB8YUDQhl6t18hw56GL43UV7IJwxMGTXM+QKAVgRO0iJ8h42aiwZFSmLC0GqsSg==","signatures":[{"sig":"MEUCIQCsqLFLleq+99CCZVLy0C4WHY+XQDLnPQjcYnC3NJYIYgIgbQCyFFsHjppWPnG+J8FnBewySexOA2Je7OY8A4eghYY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":101565},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"683786f5b043d9a96c9f49ed1f04f9dccd79eed3","scripts":{"lint":"eslint src/**/*.ts","test":"echo 'No tests configured'","build":"tsc","clean":"rm -rf dist","test:run":"jest --passWithNoTests","test:watch":"jest --watch","test:coverage":"jest --coverage","prepublishOnly":"npm run clean && npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:47a00b12-8559-4087-ae3a-beddb8a61b82"}},"repository":{"url":"git+https://github.com/bernierllc/tools.git","type":"git","directory":"packages/core/webhook-receiver"},"_npmVersion":"lerna/9.0.3/node@v20.19.6+x64 (linux)","description":"Core HTTP endpoint functionality for receiving and processing webhooks with signature validation","directories":{},"_nodeVersion":"20.19.6","publishConfig":{"access":"restricted","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","eslint":"^8.50.0","ts-jest":"^29.1.1","typescript":"^5.2.2","@types/jest":"^29.5.5","@types/node":"^20.6.3","@typescript-eslint/parser":"^6.7.2","@typescript-eslint/eslint-plugin":"^6.7.2"},"_npmOperationalInternal":{"tmp":"tmp/webhook-receiver_1.2.0_1767644249133_0.22075118721769216","host":"s3://npm-registry-packages-npm-production"}},"1.2.1":{"name":"@bernierllc/webhook-receiver","version":"1.2.1","keywords":["webhook","receiver","http","signature","validation","hmac","jwt","github","stripe"],"author":{"name":"Bernier LLC"},"license":"SEE LICENSE IN LICENSE","_id":"@bernierllc/webhook-receiver@1.2.1","maintainers":[{"name":"alikhan410","email":"mczeyo@gmail.com"},{"name":"mkbernier","email":"mkbernier@gmail.com"}],"homepage":"https://github.com/bernierllc/tools/tree/main/packages/core/webhook-receiver","bugs":{"url":"https://github.com/bernierllc/tools/issues"},"dist":{"shasum":"e9351cf55f3d7406de63d958edd95e2d31657b2e","tarball":"https://registry.npmjs.org/@bernierllc/webhook-receiver/-/webhook-receiver-1.2.1.tgz","fileCount":35,"integrity":"sha512-IQWd2p5fGcQ5Bua6mIk8zq+wvEzGHLdlYC7KE43aGUSI+b2Gic+gVGjlcIx5HVXG10qKFAGEjrh8CWKCtJ+dYQ==","signatures":[{"sig":"MEYCIQCdiRJ4/ZiuSUkzy03GYq0dZkTQYCXIfqk52KBQZ5GicAIhAIEOk+1Mth7VW5BV76Lz1UcXUu9pJRuOD3YZhcB0BRIx","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":101447},"main":"dist/index.js","type":"module","_from":"file:bernierllc-webhook-receiver-1.2.1.tgz","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"lint":"eslint src/**/*.ts","test":"echo 'No tests configured'","build":"tsc","clean":"rm -rf dist","test:run":"jest --passWithNoTests","test:watch":"jest --watch","test:coverage":"jest --coverage"},"_npmUser":{"name":"mkbernier","email":"mkbernier@gmail.com"},"_resolved":"/Users/mattbernier/projects/tools/packages/core/webhook-receiver/bernierllc-webhook-receiver-1.2.1.tgz","_integrity":"sha512-IQWd2p5fGcQ5Bua6mIk8zq+wvEzGHLdlYC7KE43aGUSI+b2Gic+gVGjlcIx5HVXG10qKFAGEjrh8CWKCtJ+dYQ==","repository":{"url":"git+https://github.com/bernierllc/tools.git","type":"git","directory":"packages/core/webhook-receiver"},"_npmVersion":"11.6.2","description":"Core HTTP endpoint functionality for receiving and processing webhooks with signature validation","directories":{},"_nodeVersion":"25.2.1","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","eslint":"^8.50.0","ts-jest":"^29.1.1","typescript":"^5.2.2","@types/jest":"^29.5.5","@types/node":"^20.6.3","@typescript-eslint/parser":"^6.7.2","@typescript-eslint/eslint-plugin":"^6.7.2"},"_npmOperationalInternal":{"tmp":"tmp/webhook-receiver_1.2.1_1772569651752_0.23330847234473873","host":"s3://npm-registry-packages-npm-production"}},"1.2.2":{"name":"@bernierllc/webhook-receiver","version":"1.2.2","keywords":["webhook","receiver","http","signature","validation","hmac","jwt","github","stripe"],"author":{"name":"Bernier LLC"},"license":"SEE LICENSE IN LICENSE","_id":"@bernierllc/webhook-receiver@1.2.2","maintainers":[{"name":"alikhan410","email":"mczeyo@gmail.com"},{"name":"mkbernier","email":"mkbernier@gmail.com"}],"homepage":"https://github.com/bernierllc/tools/tree/main/packages/core/webhook-receiver","bugs":{"url":"https://github.com/bernierllc/tools/issues"},"dist":{"shasum":"9affe18a3db4d6a66e74fa2acce9ab272fd23be7","tarball":"https://registry.npmjs.org/@bernierllc/webhook-receiver/-/webhook-receiver-1.2.2.tgz","fileCount":35,"integrity":"sha512-rtKk+jXRrbvImQk4StFAW6oClEg9JvcoI+RfUr3NIwfYKiUqu4ut4WYswvtF3Vp+X6gffLIOonQzpcVHZ8F70w==","signatures":[{"sig":"MEYCIQDupuQgY77wn12h3MxYKeVYMLJrBHhDiKHUr1HJUxOCAQIhAK6I/vUGuqjcJKptVwo03mv6vB6Tl0yWHZU4bgtKJnlJ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":101447},"main":"dist/index.js","type":"module","_from":"file:bernierllc-webhook-receiver-1.2.2.tgz","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"lint":"eslint src/**/*.ts","test":"echo 'No tests configured'","build":"tsc","clean":"rm -rf dist","test:run":"jest --passWithNoTests","test:watch":"jest --watch","test:coverage":"jest --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:47a00b12-8559-4087-ae3a-beddb8a61b82"}},"_resolved":"/home/runner/work/tools/tools/packages/core/webhook-receiver/bernierllc-webhook-receiver-1.2.2.tgz","_integrity":"sha512-rtKk+jXRrbvImQk4StFAW6oClEg9JvcoI+RfUr3NIwfYKiUqu4ut4WYswvtF3Vp+X6gffLIOonQzpcVHZ8F70w==","repository":{"url":"git+https://github.com/bernierllc/tools.git","type":"git","directory":"packages/core/webhook-receiver"},"_npmVersion":"11.11.0","description":"Core HTTP endpoint functionality for receiving and processing webhooks with signature validation","directories":{},"_nodeVersion":"20.20.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","eslint":"^8.50.0","ts-jest":"^29.1.1","typescript":"^5.2.2","@types/jest":"^29.5.5","@types/node":"^20.6.3","@typescript-eslint/parser":"^6.7.2","@typescript-eslint/eslint-plugin":"^6.7.2"},"_npmOperationalInternal":{"tmp":"tmp/webhook-receiver_1.2.2_1773161660096_0.8436145323672575","host":"s3://npm-registry-packages-npm-production"}},"1.4.0":{"name":"@bernierllc/webhook-receiver","version":"1.4.0","keywords":["webhook","receiver","http","signature","validation","hmac","jwt","github","stripe"],"author":{"name":"Bernier LLC"},"license":"SEE LICENSE IN LICENSE","_id":"@bernierllc/webhook-receiver@1.4.0","maintainers":[{"name":"alikhan410","email":"mczeyo@gmail.com"},{"name":"mkbernier","email":"mkbernier@gmail.com"}],"homepage":"https://github.com/bernierllc/tools/tree/main/packages/core/webhook-receiver","bugs":{"url":"https://github.com/bernierllc/tools/issues"},"dist":{"shasum":"f9b5b7a8e3e5ab234f6bc3ea64c9ec6cab5e3041","tarball":"https://registry.npmjs.org/@bernierllc/webhook-receiver/-/webhook-receiver-1.4.0.tgz","fileCount":39,"integrity":"sha512-9JUsfTt23NolDKldNoZBvEPpzS18BVfSa969Vib8wF4X0WZi/M5sI64IB/LAxUuJtl+YbW/7sCqOItMiDafGbw==","signatures":[{"sig":"MEQCIGwFhpQdvz0a/QQLYXkXfU8pC4A0btEAvrZmBedkUdXTAiBlvVS3y8raz2s2cH8K2nfXUNQKYkRHn07O7N9HUEK+gA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":104862},"main":"dist/index.js","type":"module","_from":"file:bernierllc-webhook-receiver-1.4.0.tgz","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"lint":"eslint src/**/*.ts","test":"echo 'No tests configured'","build":"tsc","clean":"rm -rf dist","test:run":"jest --passWithNoTests","test:watch":"jest --watch","test:coverage":"jest --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:47a00b12-8559-4087-ae3a-beddb8a61b82"}},"_resolved":"/home/runner/work/tools/tools/packages/core/webhook-receiver/bernierllc-webhook-receiver-1.4.0.tgz","_integrity":"sha512-9JUsfTt23NolDKldNoZBvEPpzS18BVfSa969Vib8wF4X0WZi/M5sI64IB/LAxUuJtl+YbW/7sCqOItMiDafGbw==","repository":{"url":"git+https://github.com/bernierllc/tools.git","type":"git","directory":"packages/core/webhook-receiver"},"_npmVersion":"11.14.1","description":"Core HTTP endpoint functionality for receiving and processing webhooks with signature validation","directories":{},"_nodeVersion":"20.20.2","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","eslint":"^8.50.0","ts-jest":"^29.1.1","typescript":"^5.2.2","@types/jest":"^29.5.5","@types/node":"^20.6.3","@typescript-eslint/parser":"^6.7.2","@typescript-eslint/eslint-plugin":"^6.7.2"},"_npmOperationalInternal":{"tmp":"tmp/webhook-receiver_1.4.0_1779241484613_0.8929406698476683","host":"s3://npm-registry-packages-npm-production"}},"1.5.0":{"name":"@bernierllc/webhook-receiver","version":"1.5.0","description":"Core HTTP endpoint functionality for receiving and processing webhooks with signature validation","type":"module","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"keywords":["webhook","receiver","http","signature","validation","hmac","jwt","github","stripe"],"author":{"name":"Bernier LLC"},"license":"SEE LICENSE IN LICENSE","devDependencies":{"@types/jest":"^29.5.5","@types/node":"^20.6.3","@typescript-eslint/eslint-plugin":"^6.7.2","@typescript-eslint/parser":"^6.7.2","eslint":"^8.50.0","jest":"^29.7.0","ts-jest":"^29.1.1","typescript":"^5.2.2"},"repository":{"type":"git","url":"git+https://github.com/bernierllc/tools.git","directory":"packages/core/webhook-receiver"},"bugs":{"url":"https://github.com/bernierllc/tools/issues"},"homepage":"https://github.com/bernierllc/tools/tree/main/packages/core/webhook-receiver","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"scripts":{"build":"tsc","test":"echo 'No tests configured'","test:coverage":"jest --coverage","test:watch":"jest --watch","test:run":"jest --passWithNoTests","lint":"eslint src/**/*.ts","clean":"rm -rf dist"},"_id":"@bernierllc/webhook-receiver@1.5.0","_integrity":"sha512-KIrpUkoOF141Ta/62SVwOLAn1nPcbL4cUKRoHp7dbSDXJypE9NHo2WduqhRD+yRig9YpoRBiQvo5pJfPj7PLBg==","_resolved":"/home/runner/work/tools/tools/packages/core/webhook-receiver/bernierllc-webhook-receiver-1.5.0.tgz","_from":"file:bernierllc-webhook-receiver-1.5.0.tgz","_nodeVersion":"20.20.2","_npmVersion":"11.14.1","dist":{"integrity":"sha512-KIrpUkoOF141Ta/62SVwOLAn1nPcbL4cUKRoHp7dbSDXJypE9NHo2WduqhRD+yRig9YpoRBiQvo5pJfPj7PLBg==","shasum":"84a9cf975cd11ff9f2d9d21e3b7397ffc51ce5a7","tarball":"https://registry.npmjs.org/@bernierllc/webhook-receiver/-/webhook-receiver-1.5.0.tgz","fileCount":39,"unpackedSize":104862,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDQRpPgAh6xJxmSiY0i6F2En9LxGrGRO0DLcACLawo/jAIhAMOGO4pJk2IkxYxiaLhEcFsAKe6FjcwCeGVh0Lso+Nch"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:47a00b12-8559-4087-ae3a-beddb8a61b82"}},"directories":{},"maintainers":[{"name":"alikhan410","email":"mczeyo@gmail.com"},{"name":"mkbernier","email":"mkbernier@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/webhook-receiver_1.5.0_1779250231182_0.9083599582193236"},"_hasShrinkwrap":false}},"time":{"created":"2025-08-29T23:03:58.971Z","modified":"2026-05-20T04:10:31.549Z","1.0.1":"2025-08-29T23:03:59.546Z","1.2.0":"2026-01-05T20:17:29.283Z","1.2.1":"2026-03-03T20:27:31.929Z","1.2.2":"2026-03-10T16:54:20.233Z","1.4.0":"2026-05-20T01:44:44.751Z","1.5.0":"2026-05-20T04:10:31.403Z"},"bugs":{"url":"https://github.com/bernierllc/tools/issues"},"author":{"name":"Bernier LLC"},"license":"SEE LICENSE IN LICENSE","homepage":"https://github.com/bernierllc/tools/tree/main/packages/core/webhook-receiver","keywords":["webhook","receiver","http","signature","validation","hmac","jwt","github","stripe"],"repository":{"type":"git","url":"git+https://github.com/bernierllc/tools.git","directory":"packages/core/webhook-receiver"},"description":"Core HTTP endpoint functionality for receiving and processing webhooks with signature validation","maintainers":[{"name":"alikhan410","email":"mczeyo@gmail.com"},{"name":"mkbernier","email":"mkbernier@gmail.com"}],"readme":"# @bernierllc/webhook-receiver\n\nCore HTTP endpoint functionality for receiving and processing webhooks with signature validation.\n\n## Installation\n\n```bash\nnpm install @bernierllc/webhook-receiver\n```\n\n## Usage\n\n### Basic Webhook Receiver\n\n```typescript\nimport { WebhookReceiver } from '@bernierllc/webhook-receiver';\n\nconst receiver = new WebhookReceiver({\n  maxPayloadSize: 1024 * 1024, // 1MB\n  signatureHeader: 'x-webhook-signature',\n  signatureSecret: process.env.WEBHOOK_SECRET,\n  signatureAlgorithm: 'hmac-sha256',\n  replayProtection: true,\n  timestampTolerance: 300 // 5 minutes\n});\n\n// Process incoming webhook\nconst payload = await receiver.processRequest({\n  method: 'POST',\n  headers: request.headers,\n  body: request.body,\n  url: request.url\n});\n\nconsole.log('Webhook received:', payload.event, payload.source);\n```\n\n### GitHub Webhook Example\n\n```typescript\nconst githubReceiver = new WebhookReceiver({\n  signatureHeader: 'x-hub-signature-256',\n  signatureSecret: process.env.GITHUB_WEBHOOK_SECRET,\n  signatureAlgorithm: 'hmac-sha256',\n  customValidator: async (payload) => {\n    // GitHub-specific validation\n    return payload.headers['user-agent']?.startsWith('GitHub-Hookshot/');\n  }\n});\n```\n\n### Stripe Webhook Example\n\n```typescript\nconst stripeReceiver = new WebhookReceiver({\n  signatureHeader: 'stripe-signature',\n  signatureSecret: process.env.STRIPE_WEBHOOK_SECRET,\n  signatureAlgorithm: 'hmac-sha256',\n  timestampHeader: 'stripe-signature', // Contains timestamp\n  timestampTolerance: 300\n});\n```\n\n## Features\n\n- **Multiple Signature Algorithms**: HMAC-SHA256, HMAC-SHA1, JWT, custom validation\n- **Automatic Source Detection**: GitHub, Stripe, GitLab, Bitbucket, Slack, Discord\n- **Replay Protection**: Timestamp validation with configurable tolerance\n- **Content Type Support**: JSON, form-data, raw text, XML\n- **Size Limits**: Configurable payload size restrictions\n- **Framework Agnostic**: Works with Express, Fastify, Next.js, Edge functions\n\n## API Reference\n\n### WebhookReceiver\n\n#### Constructor Options\n\n```typescript\ninterface ReceiverOptions {\n  maxPayloadSize?: number;      // Max payload size in bytes (default: 10MB)\n  signatureHeader?: string;     // Header containing signature\n  signatureSecret?: string;     // Secret for signature validation\n  signatureAlgorithm?: 'hmac-sha256' | 'hmac-sha1' | 'jwt' | 'custom';\n  timestampHeader?: string;     // Header containing timestamp\n  timestampTolerance?: number;  // Timestamp tolerance in seconds\n  replayProtection?: boolean;   // Enable replay protection\n  customValidator?: (payload: WebhookPayload) => Promise<boolean>;\n}\n```\n\n#### Methods\n\n- `processRequest(request: WebhookRequest): Promise<WebhookPayload>`\n- `validateSignature(payload: WebhookPayload): Promise<boolean>`\n- `validateTimestamp(payload: WebhookPayload): Promise<boolean>`\n\n### Utility Functions\n\n```typescript\n// Signature validation\nvalidateHmacSignature(payload: string | Buffer, signature: string, secret: string, algorithm: 'sha256' | 'sha1'): boolean\n\n// Request parsing\nparseHeaders(headers: Record<string, string>): ParsedHeaders\nparsePayloadData(body: Buffer | string, contentType?: string): any\n\n// Source detection\ndetectWebhookSource(headers: Record<string, string>): string\ndetectWebhookEvent(headers: Record<string, string>, data: any): string\n```\n\n## Supported Webhook Sources\n\n- GitHub (`x-github-event`, `x-hub-signature-256`)\n- Stripe (`stripe-signature`)\n- GitLab (`x-gitlab-event`)\n- Bitbucket (`x-event-key`)\n- Slack (User-Agent detection)\n- Discord (User-Agent detection)\n- Generic webhook detection\n\n## Security Features\n\n- **Signature Validation**: HMAC-SHA256/SHA1, JWT token validation\n- **Replay Protection**: Timestamp validation with configurable tolerance\n- **Input Validation**: Payload size limits, content-type validation\n- **Header Sanitization**: Removes potentially dangerous headers\n- **Timing Attack Prevention**: Constant-time signature comparison\n\n## Error Handling\n\nAll validation errors throw `WebhookError` with appropriate HTTP status codes:\n\n```typescript\ntry {\n  const payload = await receiver.processRequest(request);\n} catch (error) {\n  if (error instanceof WebhookError) {\n    // Return appropriate HTTP status\n    return new Response(error.message, { status: error.statusCode });\n  }\n  throw error;\n}\n```\n\n## Integration Status\n\n### Logger Integration\n**Status**: Optional (recommended for webhook monitoring)\n\n**Justification**: While this package can function without logging, it's highly recommended to integrate `@bernierllc/logger` for webhook event monitoring. Webhook receivers handle security-critical operations (signature validation, replay protection) and logging these events helps with security auditing, debugging, and threat detection. However, the package is designed to work without logging for environments where logging isn't available.\n\n**Pattern**: Optional integration - package works without logger, but logger enhances security monitoring capabilities.\n\n**Example Integration**:\n```typescript\nimport { Logger } from '@bernierllc/logger';\nimport { WebhookReceiver } from '@bernierllc/webhook-receiver';\n\nconst logger = new Logger({ service: 'webhook-receiver' });\nconst receiver = new WebhookReceiver({ /* config */ });\n\n// Log webhook events\nreceiver.on('webhook:received', (event) => {\n  logger.info('Webhook received', { source: event.source, timestamp: event.timestamp });\n});\n```\n\n### NeverHub Integration\n**Status**: Optional (recommended for webhook orchestration)\n\n**Justification**: While this package can function without NeverHub, it's highly recommended to integrate `@bernierllc/neverhub-adapter` for webhook orchestration and event publishing. Webhook receivers often need to coordinate with other services, and NeverHub provides a service mesh for publishing webhook events that other services can subscribe to. However, the package is designed to work without NeverHub for simpler use cases.\n\n**Pattern**: Optional integration - package works without NeverHub, but NeverHub enhances webhook orchestration capabilities.\n\n**Example Integration**:\n```typescript\nimport { NeverHubAdapter } from '@bernierllc/neverhub-adapter';\nimport { WebhookReceiver } from '@bernierllc/webhook-receiver';\n\nconst neverhub = new NeverHubAdapter({ service: 'webhook-receiver' });\nconst receiver = new WebhookReceiver({ /* config */ });\n\n// Publish webhook events to NeverHub\nreceiver.on('webhook:validated', async (event) => {\n  await neverhub.publish('webhook.received', {\n    source: event.source,\n    payload: event.payload,\n    timestamp: event.timestamp\n  });\n});\n```\n\n### Docs-Suite Integration\n**Status**: Ready\n\n**Format**: TypeDoc-compatible JSDoc comments are included throughout the source code. All public APIs are documented with examples and type information.\n\n## License\n\nCopyright (c) 2025 Bernier LLC. All rights reserved.","readmeFilename":"README.md"}