# Verify zoom webhook failed

**URL:** <https://devforum.zoom.us/t/verify-zoom-webhook-failed/113351>\
**Category:** API and Webhooks\
**Created:** [July 10, 2024, 7:09am UTC](https://devforum.zoom.us/t/verify-zoom-webhook-failed/113351 "2024-07-10T07:09:06Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![letuan1999v5](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/letuan1999v5/32/49285_2.png) [@letuan1999v5](https://devforum.zoom.us/u/letuan1999v5)\
**Post date:** [July 10, 2024, 7:09am UTC](https://devforum.zoom.us/t/verify-zoom-webhook-failed/113351/1 "2024-07-10T07:09:06Z")

</div>

I’m trying to use zoom webhook to take the create and end meeting event by using PHP.  
I have a trouble of verifying request from zoom.

According to the instruction of this document [[Using webhooks](https://developers.zoom.us/docs/api/rest/webhook-reference/) ], the hash string is the combination of [v0]:[x-zm-request-timestamp]:[request-body].

My zoom request header:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/4/f/4f06ed850f819c228fd7375bb518fd653b2bf9db.png)

My zoom request header timestamp:

```auto
$XZmRequestTimestamp = $headers['XZmRequestTimestamp'];

```

My string before hash:

```auto
$original_string = 'v0:' .$XZmRequestTimestamp .':' .json_encode($zoom_request_data);

```

The original string looks like this:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/a/f/af74403aa26d4faf84359ae125b74230e5e59b1e.png)  
My secret token:  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/1/3/13ded19a06591518a95d9883728e3912343e3cd8.png)

My hash string:

```auto
$hash_string = hash_hmac('sha256', $original_string, $credential['zoom_secret_token']);

```

But the hash string (after prepending `v0=`) is not match with the header XZmSignature from the request.

Please tell me if there is anything wrong. Thank you so much.

---

<div class="post-metadata">

**Author:** ![helpdesk3](https://avatars.discourse-cdn.com/v4/letter/h/b9bd4f/32.png) [@helpdesk3](https://devforum.zoom.us/u/helpdesk3)\
**Post date:** [July 10, 2024, 7:36pm UTC](https://devforum.zoom.us/t/verify-zoom-webhook-failed/113351/2 "2024-07-10T19:36:20Z")

</div>

Getting the same error! Signature and the req.headers[x-zm-signature] are different

---

<div class="post-metadata">

**Author:** ![gianni.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/gianni.zoom/32/32523_2.png) [@gianni.zoom](https://devforum.zoom.us/u/gianni.zoom)\
**Post date:** [July 10, 2024, 7:50pm UTC](https://devforum.zoom.us/t/verify-zoom-webhook-failed/113351/3 "2024-07-10T19:50:47Z")

</div>

Hi @helpdesk3 @letuan1999v5 given you are both seeing this, I am going to message you directly for the following info.

Respond to my private message (you’ll see in your notifications) with the following:

- email
- client id
- webhook endpoint
- webhook signatures
- screenshots of behavior
- steps to reproduce

---

<div class="post-metadata">

**Author:** ![gianni.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/gianni.zoom/32/32523_2.png) [@gianni.zoom](https://devforum.zoom.us/u/gianni.zoom)\
**Post date:** [July 23, 2024, 8:09pm UTC](https://devforum.zoom.us/t/verify-zoom-webhook-failed/113351/5 "2024-07-23T20:09:47Z")

</div>

Hi @helpdesk3 I followed up with you via private message, still waiting to hear back.

---

<div class="post-metadata">

**Author:** ![gianni.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/gianni.zoom/32/32523_2.png) [@gianni.zoom](https://devforum.zoom.us/u/gianni.zoom)\
**Post date:** [August 11, 2024, 3:57pm UTC](https://devforum.zoom.us/t/verify-zoom-webhook-failed/113351/6 "2024-08-11T15:57:02Z")

</div>

Working through some issues with developer’s account – unable to verify through support system.

---

<div class="post-metadata">

**Author:** ![agebold](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/agebold/32/65416_2.png) [@agebold](https://devforum.zoom.us/u/agebold)\
**Post date:** [December 5, 2024, 12:59am UTC](https://devforum.zoom.us/t/verify-zoom-webhook-failed/113351/7 "2024-12-05T00:59:26Z")

</div>

was there a resolution to this? I’m running into this now as well.

---

<div class="post-metadata">

**Author:** ![letuan1999v5](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/letuan1999v5/32/49285_2.png) [@letuan1999v5](https://devforum.zoom.us/u/letuan1999v5)\
**Post date:** [December 6, 2024, 8:23am UTC](https://devforum.zoom.us/t/verify-zoom-webhook-failed/113351/8 "2024-12-06T08:23:20Z")

</div>

I have used Authentication Header Option instead.
