Skip to main content
Telnyx signs every webhook delivery with an ED25519 signature carried in the telnyx-signature-ed25519 and telnyx-timestamp request headers. The SDK’s webhook helper verifies the signature against your account’s public key and parses the payload into a typed event. Copy your public key from the Mission Control Portal and expose it as TELNYX_PUBLIC_KEY — the client reads it automatically, the same way it reads TELNYX_API_KEY:

Verify and parse an event

Pass the raw request body and the request headers to client.webhooks.unwrap(). Verification needs the exact bytes Telnyx sent, so read the body as text rather than letting the framework parse it first:
unwrap() throws when the signature does not match, and returns the parsed event as a typed union of every webhook event the API sends — narrow on event.data?.event_type to handle specific events.

Skipping verification

client.webhooks.unsafeUnwrap(body) parses a payload without checking the signature. Only use it for payloads you have already verified by other means, or in tests.