# What's wrong with my PHP code to validate Webhook Endpoint?

**URL:** <https://devforum.zoom.us/t/whats-wrong-with-my-php-code-to-validate-webhook-endpoint/82606>\
**Category:** API and Webhooks\
**Tags:** webhooks\
**Created:** [February 5, 2023, 10:59am UTC](https://devforum.zoom.us/t/whats-wrong-with-my-php-code-to-validate-webhook-endpoint/82606 "2023-02-05T10:59:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vnkmd](https://avatars.discourse-cdn.com/v4/letter/v/3bc359/32.png) [@vnkmd](https://devforum.zoom.us/u/vnkmd)\
**Post date:** [February 5, 2023, 10:59am UTC](https://devforum.zoom.us/t/whats-wrong-with-my-php-code-to-validate-webhook-endpoint/82606/1 "2023-02-05T10:59:55Z")

</div>

PHP7.4

I have entered the endpoint as [myserver.com/mypath/myfile.php](http://myserver.com/mypath/myfile.php)

in myfile.php:

> $zoomData = json\_decode(file\_get\_contents(‘php://input’), true);  
> $zoomSecret = ‘asdfsdfsdf’; //actual secret\_id that I had got along with the client\_id is entered here
> 
> $zoomPlainToken = $zoomData[‘payload’][‘plainToken’];  
> $sig = hash\_hmac(‘sha256’, $zoomPlainToken, $zoomSecret);
> 
> $reponseData[‘plainToken’] = $zoomPlainToken;  
> $reponseData[‘encryptedToken’] = $sig;  
> echo json\_encode($reponseData);

The validation always fails!

the $reponseData looks like this:

> {  
> “plainToken”: “PfgPl4NVSQW\_rGbmqH935Q”,  
> “encryptedToken”: “da33eccc18b883c91b4ed68d4d452b9d435d69a63370e2bac5ae67d1d7d46f59”  
> }

What is wrong? I can’t seem to get my head around this…

Thanks

---

<div class="post-metadata">

**Author:** ![vnkmd](https://avatars.discourse-cdn.com/v4/letter/v/3bc359/32.png) [@vnkmd](https://devforum.zoom.us/u/vnkmd)\
**Post date:** [February 5, 2023, 11:11am UTC](https://devforum.zoom.us/t/whats-wrong-with-my-php-code-to-validate-webhook-endpoint/82606/2 "2023-02-05T11:11:22Z")

</div>

AAARRRRRGGGGG

The “secret” is not the “client secret” but… the secret token on the same page where have to validate

DDDDUUUUUHHHH

The docs need to mention this specifically 🙂 or maybe it was just me

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [February 9, 2024, 2:48am UTC](https://devforum.zoom.us/t/whats-wrong-with-my-php-code-to-validate-webhook-endpoint/82606/3 "2024-02-09T02:48:11Z")

</div>

This topic was automatically closed 368 days after the last reply. New replies are no longer allowed.
