{"_id":"@cm-email-gateway/email-webhook-verification","_rev":"3-157f53946f8ab1ea475ed8a32613c813","name":"@cm-email-gateway/email-webhook-verification","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.0":{"name":"@cm-email-gateway/email-webhook-verification","version":"1.0.0","keywords":["webhook","verification","hmac","signature","email","cm"],"author":{"name":"email-team"},"license":"MIT","_id":"@cm-email-gateway/email-webhook-verification@1.0.0","maintainers":[{"name":"lord_sylar","email":"lalit.bisht@cm.com"}],"homepage":"https://github.com/cmdotcom/email-webhook-verification-sdks#readme","bugs":{"url":"https://github.com/cmdotcom/email-webhook-verification-sdks/issues"},"dist":{"shasum":"608403122c1d88608cc04240a7ea2c02f8fbc3ee","tarball":"https://registry.npmjs.org/@cm-email-gateway/email-webhook-verification/-/email-webhook-verification-1.0.0.tgz","fileCount":33,"integrity":"sha512-mkjmSZ4VnNQ9RxjofCr8VHabSH2YZyhVhuo3rM0aeoVZHSN3AV/dpoXOgHeA6JMoY84/xdvWtmK0VNl9EGCXnw==","signatures":[{"sig":"MEUCIE7UH+YTXbxn5KtNJLY1OscEdVgOXyOmJm3kjMIgLDh7AiEAgb324BZsKspkoKtc4p+nobbZY16RyLSMB49y8q48Z+k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":30321},"main":"dist/cjs/index.js","types":"dist/types/index.d.ts","module":"dist/esm/index.js","engines":{"node":">=16.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","import":"./dist/esm/index.js","require":"./dist/cjs/index.js"}},"gitHead":"42cb11f9315ce381ad4fbf742ac782e8d8f611e4","scripts":{"lint":"eslint src/**/*.ts","test":"node --experimental-vm-modules node_modules/jest/bin/jest.js","build":"npm run build:cjs && npm run build:esm && npm run build:types","build:cjs":"tsc -p tsconfig.cjs.json","build:esm":"tsc -p tsconfig.esm.json","build:types":"tsc -p tsconfig.types.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"lord_sylar","email":"lalit.bisht@cm.com"},"repository":{"url":"git+https://github.com/cmdotcom/email-webhook-verification-sdks.git","type":"git"},"_npmVersion":"10.8.2","description":"SDK for verifying CM Email webhook signatures","directories":{},"_nodeVersion":"20.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.1.2","typescript":"^5.3.3","@types/jest":"^29.5.12","@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/email-webhook-verification_1.0.0_1773036838834_0.0023263506200574824","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@cm-email-gateway/email-webhook-verification","version":"1.0.1","keywords":["webhook","verification","hmac","signature","email","cm"],"author":{"name":"email-team"},"license":"MIT","_id":"@cm-email-gateway/email-webhook-verification@1.0.1","maintainers":[{"name":"lord_sylar","email":"lalit.bisht@cm.com"}],"homepage":"https://github.com/cmdotcom/email-webhook-verification-sdks#readme","bugs":{"url":"https://github.com/cmdotcom/email-webhook-verification-sdks/issues"},"dist":{"shasum":"556fca2d6436ea289619520956bff39113f6b27b","tarball":"https://registry.npmjs.org/@cm-email-gateway/email-webhook-verification/-/email-webhook-verification-1.0.1.tgz","fileCount":33,"integrity":"sha512-Va2LHBDMpGDHcN5npkrSjWn/hnO3PRrLL9r8JQpBOKY0gEamxG0yIewrt7wUtgmpsZ4JGRO2tr5ygbPYToRlOA==","signatures":[{"sig":"MEUCIGPnPtA6UKFdZ/ugpgZiOM3Qbp7QNB6Y6RbTOq5fEsaJAiEAgThKv30mPnrF5tiHMJsUIw8SRL+M3/zleK+Y7hDY4rc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":30391},"main":"dist/cjs/index.js","types":"dist/types/index.d.ts","module":"dist/esm/index.js","engines":{"node":">=16.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","import":"./dist/esm/index.js","require":"./dist/cjs/index.js"}},"gitHead":"cc78fcc062e08f934fb3dad60d5674c0d511596f","scripts":{"lint":"eslint src/**/*.ts","test":"node --experimental-vm-modules node_modules/jest/bin/jest.js","build":"npm run build:cjs && npm run build:esm && npm run build:types","build:cjs":"tsc -p tsconfig.cjs.json","build:esm":"tsc -p tsconfig.esm.json","build:types":"tsc -p tsconfig.types.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"lord_sylar","email":"lalit.bisht@cm.com"},"repository":{"url":"git+https://github.com/cmdotcom/email-webhook-verification-sdks.git","type":"git"},"_npmVersion":"10.8.2","description":"SDK for verifying CM Email webhook signatures","directories":{},"_nodeVersion":"20.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.1.2","typescript":"^5.3.3","@types/jest":"^29.5.12","@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/email-webhook-verification_1.0.1_1773054345891_0.6612958255441095","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@cm-email-gateway/email-webhook-verification","version":"1.0.2","description":"SDK for verifying CM Email webhook signatures","main":"dist/cjs/index.js","module":"dist/esm/index.js","types":"dist/types/index.d.ts","exports":{".":{"require":"./dist/cjs/index.js","import":"./dist/esm/index.js","types":"./dist/types/index.d.ts"}},"scripts":{"build":"npm run build:cjs && npm run build:esm && npm run build:types","build:cjs":"tsc -p tsconfig.cjs.json","build:esm":"tsc -p tsconfig.esm.json","build:types":"tsc -p tsconfig.types.json","test":"node --experimental-vm-modules node_modules/jest/bin/jest.js","lint":"eslint src/**/*.ts","prepublishOnly":"npm run build"},"keywords":["webhook","verification","hmac","signature","email","cm"],"author":{"name":"email-team"},"license":"MIT","publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/cmdotcom/email-webhook-verification-sdks.git"},"engines":{"node":">=16.0.0"},"overrides":{"handlebars":">=4.7.9"},"devDependencies":{"@types/jest":"^29.5.12","@types/node":"^20.11.0","jest":"^29.7.0","ts-jest":"^29.1.2","typescript":"^5.3.3"},"_id":"@cm-email-gateway/email-webhook-verification@1.0.2","gitHead":"0634ca539bb1a4a44b2d86765a7d2d83c6b954be","bugs":{"url":"https://github.com/cmdotcom/email-webhook-verification-sdks/issues"},"homepage":"https://github.com/cmdotcom/email-webhook-verification-sdks#readme","_nodeVersion":"20.20.1","_npmVersion":"10.8.2","dist":{"integrity":"sha512-Ah79J7hKvyDflZuolqkDO11OqY81cnWpGGTQAjdUa3fdgyXfCLZb23ekOdy8COQ2Raa6YKn4GhK647m68+VT4A==","shasum":"32292c5ce6505ba0a689c31a3fe8f49e3e759739","tarball":"https://registry.npmjs.org/@cm-email-gateway/email-webhook-verification/-/email-webhook-verification-1.0.2.tgz","fileCount":33,"unpackedSize":30441,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCTQgYWGWmnzk/74pO5Muqsn9AQVpozLgtOyguHdR9+EQIhANIrSTT3wUZBfT2YK8rYBzP8TzMXZxOSDRB6JOHM/7x/"}]},"_npmUser":{"name":"lord_sylar","email":"lalit.bisht@cm.com"},"directories":{},"maintainers":[{"name":"lord_sylar","email":"lalit.bisht@cm.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/email-webhook-verification_1.0.2_1775108926541_0.3759169489147891"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-09T06:13:58.740Z","modified":"2026-04-02T05:48:46.857Z","1.0.0":"2026-03-09T06:13:58.986Z","1.0.1":"2026-03-09T11:05:46.060Z","1.0.2":"2026-04-02T05:48:46.723Z"},"bugs":{"url":"https://github.com/cmdotcom/email-webhook-verification-sdks/issues"},"author":{"name":"email-team"},"license":"MIT","homepage":"https://github.com/cmdotcom/email-webhook-verification-sdks#readme","keywords":["webhook","verification","hmac","signature","email","cm"],"repository":{"type":"git","url":"git+https://github.com/cmdotcom/email-webhook-verification-sdks.git"},"description":"SDK for verifying CM Email webhook signatures","maintainers":[{"name":"lord_sylar","email":"lalit.bisht@cm.com"}],"readme":"# @cm-email-gateway/email-webhook-verification\n\nNode.js/TypeScript SDK for verifying CM Email webhook signatures.\n\n## Installation\n\n```bash\nnpm install @cm-email-gateway/email-webhook-verification\n```\n\nOr with yarn:\n\n```bash\nyarn add @cm-email-gateway/email-webhook-verification\n```\n\n## Requirements\n\n- Node.js 16.0.0 or later\n\n## Usage\n\n```typescript\nimport { WebhookValidator } from '@cm-email-gateway/email-webhook-verification';\n\n// Initialize the validator with your secret key\nconst validator = new WebhookValidator({\n  secretKey: 'your-secret-key',\n});\n\n// Or with custom tolerance (default is 300 seconds)\nconst validator = new WebhookValidator({\n  secretKey: 'your-secret-key',\n  toleranceInSeconds: 600,\n});\n\n// Extract headers from the incoming webhook request\nconst headers = {\n  'svix-id': req.headers['svix-id'],\n  'svix-timestamp': req.headers['svix-timestamp'],\n  'svix-signature': req.headers['svix-signature'],\n};\n\n// Get the raw request body\nconst payload = req.body; // raw string body\n\n// Verify and parse the webhook payload\ntry {\n  const data = validator.verify<YourWebhookType>(payload, headers);\n  // Process the verified webhook data\n} catch (error) {\n  if (error instanceof MissingHeadersError) {\n    // Required headers are missing\n  } else if (error instanceof InvalidTimestampError) {\n    // Timestamp format is invalid\n  } else if (error instanceof TimestampExpiredError) {\n    // Webhook timestamp is outside the allowed tolerance window\n  } else if (error instanceof InvalidSignatureError) {\n    // Signature verification failed\n  }\n}\n```\n\n## Express.js Example\n\n```typescript\nimport express from 'express';\nimport { WebhookValidator, WebhookVerificationError } from '@cm-email-gateway/email-webhook-verification';\n\nconst app = express();\napp.use(express.raw({ type: 'application/json' }));\n\nconst validator = new WebhookValidator({\n  secretKey: process.env.WEBHOOK_SECRET_KEY!,\n});\n\napp.post('/webhook', (req, res) => {\n  try {\n    const data = validator.verify(req.body.toString(), req.headers);\n    // Process webhook\n    res.status(200).send('OK');\n  } catch (error) {\n    if (error instanceof WebhookVerificationError) {\n      res.status(401).send('Unauthorized');\n    } else {\n      res.status(500).send('Internal Server Error');\n    }\n  }\n});\n```\n\n## API\n\n### WebhookValidator\n\n#### Constructor Options\n\n| Option | Type | Default | Description |\n|--------|------|---------|-------------|\n| `secretKey` | `string` | required | Your webhook secret key |\n| `toleranceInSeconds` | `number` | `300` | Maximum age of webhook in seconds |\n\n#### Methods\n\n- `verify<T>(payload: string, headers: WebhookHeaders): T` - Verifies the webhook signature and returns the parsed payload\n\n### Errors\n\n| Error | Description |\n|-------|-------------|\n| `MissingHeadersError` | One or more required headers (`svix-id`, `svix-timestamp`, `svix-signature`) are missing |\n| `InvalidTimestampError` | The timestamp header is not a valid format |\n| `TimestampExpiredError` | The webhook timestamp is outside the allowed tolerance window |\n| `InvalidSignatureError` | The signature does not match the expected value |\n\nAll errors extend `WebhookVerificationError`.\n\n## License\n\nMIT License - see [LICENSE](../LICENSE) for details.\n\n\n","readmeFilename":"README.md"}