# Validate your webhook endpoint in WordPress

**URL:** <https://devforum.zoom.us/t/validate-your-webhook-endpoint-in-wordpress/81001>\
**Category:** API and Webhooks\
**Created:** [January 5, 2023, 1:42pm UTC](https://devforum.zoom.us/t/validate-your-webhook-endpoint-in-wordpress/81001 "2023-01-05T13:42:54Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![bmahot](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/bmahot/32/44204_2.png) [@bmahot](https://devforum.zoom.us/u/bmahot)\
**Post date:** [January 5, 2023, 1:42pm UTC](https://devforum.zoom.us/t/validate-your-webhook-endpoint-in-wordpress/81001/1 "2023-01-05T13:42:54Z")

</div>

Hi,  
i need help to validate the event notification endpoint URL for a Webhook only app in WordPress, so with PHP code  
[https://marketplace.zoom.us/docs/api-reference/webhook-reference/#validate-your-webhook-endpoint](https://marketplace.zoom.us/docs/api-reference/webhook-reference/#validate-your-webhook-endpoint)

my code :

```auto
add_action( 'rest_api_init', function () {

    register_rest_route( 'zoom/v1', '/webinar/registration', array(
        'methods' => 'POST',
        'callback' => 'zoom_registration',
        'permission_callback' => function() { return true; }
    ) );

} );

function zoom_registration( WP_REST_Request $request ){
    $parameters = $request->get_params();
    if( 'endpoint.url_validation' == $parameters['event'] ):
        $response = zoom_url_validate( $parameters );
        return new WP_REST_Response( $response, 200 );
    endif;
    return false;
}

function zoom_url_validate( $parameters ){
    $plainToken = $parameters['payload']['plainToken'];
    $encryptedToken = hash_hmac( 'sha256', $plainToken, ZOOM_SECRET_TOKEN, false );
    $hashForValidate = $encryptedToken;
    $return = ["plainToken" => $plainToken, "encryptedToken" => $hashForValidate];
    $response = json_encode( $return );
    return $response;
}

```

**Error in Zoom marketplace Apps**  
URL validation failed. Try again later.

---

<div class="post-metadata">

**Author:** ![rarev](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rarev/32/38939_2.png) [@rarev](https://devforum.zoom.us/u/rarev)\
**Post date:** [January 5, 2023, 6:06pm UTC](https://devforum.zoom.us/t/validate-your-webhook-endpoint-in-wordpress/81001/2 "2023-01-05T18:06:22Z")

</div>

Hey @bmahot

Could you print out what this function returns, you should be returning something that looks like this:

```auto
 response.json({
    "plainToken": request.body.payload.plainToken,
    "encryptedToken": hashForValidate
  })

```

This is an example in node.

> [@bmahot](#):
>
> ```auto
> function zoom_registration( WP_REST_Request $request ){
> $parameters = $request->get_params();
> if( 'endpoint.url_validation' == $parameters['event'] ):
> $response = zoom_url_validate( $parameters );
> return new WP_REST_Response( $response, 200 );
> endif;
> return false;
> }
> 
> ```

Also I would check that your hashForValidate and encyptedToken do match.

Thanks!

---

<div class="post-metadata">

**Author:** ![bmahot](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/bmahot/32/44204_2.png) [@bmahot](https://devforum.zoom.us/u/bmahot)\
**Post date:** [January 6, 2023, 8:54am UTC](https://devforum.zoom.us/t/validate-your-webhook-endpoint-in-wordpress/81001/3 "2023-01-06T08:54:20Z")

</div>

thanks for your help,

this is the parameters i receive :

```auto
Array
(
    [payload] => Array
        (
            [plainToken] => Yha30ltKQ5umDj64hxvm7Q
        )

    [event_ts] => 1672994909086
    [event] => endpoint.url_validation
)

```

this is the JSON response :

```auto
{"plainToken":"Yha30ltKQ5umDj64hxvm7Q","encryptedToken":"eaef0c687cb91968e06f33d059e924e367700e9466e08c3922d269a8bfd4f8aa"}

```

and this is what i send in response :

```auto
WP_REST_Response Object
(
    [data] => {"plainToken":"Yha30ltKQ5umDj64hxvm7Q","encryptedToken":"eaef0c687cb91968e06f33d059e924e367700e9466e08c3922d269a8bfd4f8aa"}
    [headers] => Array
        (
        )

    [status] => 200
    [links:protected] => Array
        (
        )

    [matched_route:protected] => 
    [matched_handler:protected] => 
)

```

---

<div class="post-metadata">

**Author:** ![freelancer.nak](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/freelancer.nak/32/40968_2.png) [@freelancer.nak](https://devforum.zoom.us/u/freelancer.nak)\
**Post date:** [January 7, 2023, 6:36pm UTC](https://devforum.zoom.us/t/validate-your-webhook-endpoint-in-wordpress/81001/4 "2023-01-07T18:36:06Z")

</div>

@bmahot hope you will be fine.

Here is the working solution for WP 👇

```auto
add_action('rest_api_init', function () {

    register_rest_route('/api/zoom/', '/events', array(
        'methods' => 'POST',
        'callback' => 'zoom_events',
        'permission_callback' => function () {
            return true; }
    ));

});

function zoom_events(WP_REST_Request $request)
{
    $parameters = $request->get_params();
    if ('endpoint.url_validation' == $parameters['event']):
        $response = zoom_url_validate($parameters);
        return new WP_REST_Response($response, 200);
    endif;
    return false;
}

function zoom_url_validate($parameters)
{
    $plainToken = $parameters['payload']['plainToken'];
    $encryptedToken = hash_hmac("sha256", $plainToken, "Your-Secret-Token");
    return ["plainToken" => $plainToken, "encryptedToken" => $encryptedToken];
}

```

Any query still please ask. Thanks

---

<div class="post-metadata">

**Author:** ![freelancer.nak](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/freelancer.nak/32/40968_2.png) [@freelancer.nak](https://devforum.zoom.us/u/freelancer.nak)\
**Post date:** [January 7, 2023, 6:37pm UTC](https://devforum.zoom.us/t/validate-your-webhook-endpoint-in-wordpress/81001/5 "2023-01-07T18:37:06Z")

</div>

> [@bmahot](#):
>
> ` $response = json_encode( $return );`

@bmahot You have problem here 👆 no need to json\_encode.

---

<div class="post-metadata">

**Author:** ![bmahot](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/bmahot/32/44204_2.png) [@bmahot](https://devforum.zoom.us/u/bmahot)\
**Post date:** [January 9, 2023, 10:48am UTC](https://devforum.zoom.us/t/validate-your-webhook-endpoint-in-wordpress/81001/6 "2023-01-09T10:48:12Z")

</div>

@freelancer.nak great thanks ! it’s working now

---

<div class="post-metadata">

**Author:** ![freelancer.nak](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/freelancer.nak/32/40968_2.png) [@freelancer.nak](https://devforum.zoom.us/u/freelancer.nak)\
**Post date:** [January 9, 2023, 10:49am UTC](https://devforum.zoom.us/t/validate-your-webhook-endpoint-in-wordpress/81001/7 "2023-01-09T10:49:58Z")

</div>

@bmahot Great. Welcome & Thanks 🙂

---

<div class="post-metadata">

**Author:** ![Segwe](https://avatars.discourse-cdn.com/v4/letter/s/91b2a8/32.png) [@Segwe](https://devforum.zoom.us/u/Segwe)\
**Post date:** [January 17, 2023, 7:13pm UTC](https://devforum.zoom.us/t/validate-your-webhook-endpoint-in-wordpress/81001/8 "2023-01-17T19:13:23Z")

</div>

@bmahot @freelancer.nak  
Hi,  
I am dealing with the webhook validation on wordpress too.  
I usually work with webhooks smoothly but I am struggling with the zoom validation step here.

Would you please tell me how to make this solution for wp work?  
Is it ok to add it in functions.php?

I usually set a webhook with uncanny automator (a plugin that can receive webhooks), that receives and transform data as I need.  
So the url webhook to set in the zoom webhookonly app is defined by uncanny automator.

Does this function “intercept” and anwser to any webhook received to the website domain?  
Or is there a place to write the specific url webhook?

Thank you 🙂

---

<div class="post-metadata">

**Author:** ![carlos\_venn](https://avatars.discourse-cdn.com/v4/letter/c/ee59a6/32.png) [@carlos\_venn](https://devforum.zoom.us/u/carlos_venn)\
**Post date:** [August 7, 2023, 7:31pm UTC](https://devforum.zoom.us/t/validate-your-webhook-endpoint-in-wordpress/81001/9 "2023-08-07T19:31:21Z")

</div>

hello , i have the same issue and i also try to copy and paste that solution and didnt work

this is my code

```auto
add_action('rest_api_init', function () {
    register_rest_route('/api/zoom', '/videoZoomAPI', array(
        'methods' => 'POST',
        'callback' => "zoomToApi2",
        'permission_callback' => function () {
            return true; }
    ));
});

function zoomToApi2(WP_REST_Request $data){
    $event = $data->get_param('event');
    $parameters = $data->get_params();

    if($event === 'endpoint.url_validation') {
        $ZOOM_WEBHOOK_SECRET_TOKEN = 'ZFSt84hPRrqMA4whJXvHlQ';

        $response = zoom_url_validate($parameters,$ZOOM_WEBHOOK_SECRET_TOKEN);

    }
    return new WP_REST_Response($response, 200);
}
function zoom_url_validate($parameters,$ZOOM_WEBHOOK_SECRET_TOKEN)
{
    $plainToken = $parameters['payload']['plainToken'];
    $encryptedToken = hash_hmac("sha256", $plainToken, $ZOOM_WEBHOOK_SECRET_TOKEN);
    return ["plainToken" => $plainToken, "encryptedToken" => $encryptedToken];
}

```

i add in my functions.php

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [August 10, 2024, 11:08am UTC](https://devforum.zoom.us/t/validate-your-webhook-endpoint-in-wordpress/81001/10 "2024-08-10T11:08:12Z")

</div>

This topic was automatically closed 368 days after the last reply. New replies are no longer allowed.
