Subscribe to Bob (HiBob) Webhooks v2 and verify event authenticity with the HMAC signature

domain: hr-payroll · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. In Bob, open a module's Webhooks section (Employee, Time off, Task, Docs, or Workforce planning events) and add a webhook pointing to a public HTTPS endpoint
  2. Respond immediately with HTTP 200 to Bob's initial "Ping test" POST to validate the connection
  3. On each event, read the v2 payload's type, triggeredBy, triggeredAt, and data fields, then call Bob's API to fetch the full record referenced by the entity ID
  4. Compute HMAC-SHA512 over the raw request body using the webhook secret from the Bob UI, base64-encode it, and compare against the Bob-Signature header
  5. Return HTTP 200 within Bob's timeout window to avoid entering the retry queue

Known gotchas

Related routes

Subscribe to Lodgify webhooks and verify inbound event payloads using HMAC signature validation
docs.lodgify.com · 5 steps · unrated
Subscribe to Dwolla webhooks and verify each event's HMAC signature before trusting a transfer status change
developers.dwolla.com · 5 steps · unrated
Register a Famly webhook endpoint and verify inbound event authenticity via HMAC signature
help.famly.co · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans