hubspot-webhooks
Installation
SKILL.md
HubSpot Webhooks
When to Use This Skill
- Setting up HubSpot webhook handlers
- Verifying
X-HubSpot-Signature-v3headers - Debugging signature verification failures
- Handling CRM events like contact creation, property changes, or deal events
- Migrating from HubSpot signature v1/v2 to v3
Essential Code (USE THIS)
HubSpot's official SDKs ship a signature helper: Signature.isValid in Node (@hubspot/api-client) and PHP, Signature.is_valid in Python and Ruby. The examples here verify manually with HMAC-SHA256 and base64 so the signed string and the timing-safe comparison are explicit; see references/verification.md for the SDK route.
HubSpot Signature Verification (JavaScript)
const crypto = require('crypto');