Are you looking for test card numbers?

Would you like to contact support?

Developer-resource icon

Verify HMAC signatures

Verify the integrity of webhook events using HMAC signatures.

To protect your server from unauthorised webhook events, we strongly recommend that you use Hash-based message authentication code (HMAC) signatures. After you enable HMAC signatures, each webhook event will include a signature calculated using a secret HMAC key and a payload from the webhook. By verifying this signature, you confirm that the webhook was sent by Adyen, and was not modified during transmission.

To verify HMAC signatures, you can either:

Enable HMAC signatures

To enable HMAC signed webhook events, generate a secret HMAC key in your Customer Area. The secret HMAC key is linked to a standard webhook endpoint. If you have multiple endpoints for receiving webhooks, you need to generate an HMAC key for each of them.

You also need to generate a new HMAC key when you switch from test to live.

To start receiving HMAC signed webhooks:

  1. Log in to your Customer Area. If you have set up webhooks for your merchant accounts, switch to the merchant account.
  2. Go to DevelopersWebhooks.
  3. Select the edit icon for the Standard webhook you want to enable HMAC for.
  4. Under Security, select the edit icon for HMAC key.
  5. Select Generate.
  6. Copy the HMAC key using the copy icon . Store it securely in your system - you won't be able to restore it later.
  7. Select Apply, then Save changes.

The HMAC key will now be used to sign webhook events that we send to your server. The signature is
included in the additionalData field:


If you generate a new HMAC key, make sure that you can still accept webhooks signed with your previous HMAC key for some time, because:

  • It can take some time to propagate the new key in our infrastructure.
  • HMAC signatures are calculated when the webhook payload is generated, so any webhook events queued before you saved the new key are signed using your previous key.

Verify using our libraries

You can verify signatures using our:

Verify using your own solution

To build your own solution for verifying HMAC signatures, follow these steps:

Step 1: Construct the payload

The values used below are from an example webhook. To test your solution, replace the values with actual values that you receive in a webhook event.

Concatenate the following values from the webhook event, in the given order:

Key Value
pspReference 7914073381342284
merchantAccountCode TestMerchant
merchantReference TestPayment-1407325143704
value 1130
currency EUR
success true

Assign an empty string to any fields that are empty, and use a colon (":") to delimit the values.

For the above values, with an empty originalReference, you get:


Step 2: Calculate the HMAC signature

  1. Convert the payload that you constructed to a binary representation, given the UTF-8 charset.

  2. Convert the hexadecimal HMAC key that you generated in your Customer Area to a binary representation, given the UTF-8 charset.

  3. Calculate an HMAC using:

    • The SHA256 function.
    • The binary representation of the payload.
    • The binary representation of the HMAC key.
  4. To get the final signature, Base64-encode the result.

Step 3: Compare signatures

If the signature that you calculated in Step 2 matches the hmacSignature that you received, you'll know that the webhook event was sent by Adyen and was not modified during transmission.


Sample HMAC key:


Sample webhook event signed using the above HMAC key:


See also