telnyx-signature-ed25519 and telnyx-timestamp request headers. The SDK’s
webhook helper verifies the signature against your account’s public key and
parses the payload into a typed event.
Copy your public key from the Mission Control Portal and expose it as
TELNYX_PUBLIC_KEY — the client reads it automatically, the same way it reads
TELNYX_API_KEY:
Verify and parse an event
Pass the raw request body and the request headers toclient.webhooks.unwrap().
Verification needs the exact bytes Telnyx sent, so read the body as text rather
than letting the framework parse it first:
unwrap() throws when the signature does not match, and returns the parsed
event as a typed union of every webhook event the API sends — narrow on
event.data?.event_type to handle specific events.
Skipping verification
client.webhooks.unsafeUnwrap(body) parses a payload without checking the
signature. Only use it for payloads you have already verified by other means,
or in tests.
Related
- Receiving webhooks covers delivery, retries, and failover URLs.
- Errors, retries, and timeouts covers the SDK’s error classes.