# Incoming Webhook Authentication

**URL:** <https://community.make.com/t/incoming-webhook-authentication/15219>\
**Category:** Beginner Questions\
**Tags:** webhooks\
**Created:** [September 1, 2023, 2:28am UTC](https://community.make.com/t/incoming-webhook-authentication/15219 "2023-09-01T02:28:31Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kari\_G](https://avatars.discourse-cdn.com/v4/letter/k/ed655f/32.png) [@Kari\_G](https://community.make.com/u/Kari_G)\
**Post date:** [September 1, 2023, 2:28am UTC](https://community.make.com/t/incoming-webhook-authentication/15219/1 "2023-09-01T02:28:31Z")

</div>

Hello!

I am new to Make. I would like to authenticate my incoming webhooks. My source app allows me to configure any of these authentication strategies when sending a webhook from their side:

HMAC (message + secret key hashed using sha256 algorithm, encoded base64)  
Appending an API key to the header  
Basic Auth  
Bearer Token

I am having difficulty figuring out how to set up Make webhooks so that incoming messages are authenticated before the payload is passed on. I think I need to enable “Get Request Headers” in the webhook itself, but then do I authenticate using a filter, or do I use another module? If the former, how do I configure the filter (I think I saw some documentation re: map and get + sha256 but I don’t completely understand it.) If the latter, which module(s) should I use and how would I configure it to authenticate using any of the four authentication strategies listed above?

Thank you so much!

Kari

---

<div class="post-metadata">

**Author:** ![DavidGurr\_Make](https://dub1.discourse-cdn.com/flex013/user_avatar/community.make.com/davidgurr_make/32/4624_2.png) [@DavidGurr\_Make](https://community.make.com/u/DavidGurr_Make)\
**Post date:** [September 1, 2023, 2:43am UTC](https://community.make.com/t/incoming-webhook-authentication/15219/2 "2023-09-01T02:43:45Z")

</div>

Hey @Kari_G - welcome to the Community!

That’s a great question. The key (pun intended) is in how you check the validity of the authentication. You’ll need some kind of store to hold valid keys, messages or tokens.

You could hold those in a Google Sheet, Airtable base or any other app that can store and retrieve data. But for speed (which is likely to be important in a Webhook response) it may be best to use a Make [Data Store](https://www.make.com/en/help/tools/data-store).

The only downside is that editing large amounts of data in a Data Store isn’t easy as the UI isn’t really designed for that - so if you expect to have a lot of data in there, you might need an additional scenario that manages it through a forms front-end.

After you’ve checked the authentication validity, if it fails you should use the [Webhook Response](https://www.make.com/en/help/tools/webhooks#responding-to-webhooks) module to send a 401 error with a suitable body text.

---

<div class="post-metadata">

**Author:** ![samliew](https://dub1.discourse-cdn.com/flex013/user_avatar/community.make.com/samliew/32/13327_2.png) [@samliew](https://community.make.com/u/samliew)\
**Post date:** [September 1, 2023, 3:35am UTC](https://community.make.com/t/incoming-webhook-authentication/15219/3 "2023-09-01T03:35:36Z")

</div>

Welcome to the Make community!

You could just add a filter immediately after the trigger, and check one of the following:

- the payload contains a property matching a secret string  

- custom header name contains a value like this  

If you are on an Enterprise plan, you could replace the value “password” with a Custom Variable stored in your team. That way you don’t have to update each filter for all your webhook scenarios when you only want to rotate the token value.

---

<div class="post-metadata">

**Author:** ![Kari\_G](https://avatars.discourse-cdn.com/v4/letter/k/ed655f/32.png) [@Kari\_G](https://community.make.com/u/Kari_G)\
**Post date:** [September 1, 2023, 4:00am UTC](https://community.make.com/t/incoming-webhook-authentication/15219/4 "2023-09-01T04:00:19Z")

</div>

Thank you for responding to me so quickly and for your warm welcome, David! I really appreciate it you taking the time to do so! I’ll check out the Webhook Response module - I think that will come in very handy.

Thank you!

-Kari

---

<div class="post-metadata">

**Author:** ![Kari\_G](https://avatars.discourse-cdn.com/v4/letter/k/ed655f/32.png) [@Kari\_G](https://community.make.com/u/Kari_G)\
**Post date:** [September 1, 2023, 4:14am UTC](https://community.make.com/t/incoming-webhook-authentication/15219/5 "2023-09-01T04:14:32Z")

</div>

Wow! Thank you Sam for this quick and very helpful response! And thank your for the welcome too. I think both of these solutions will do the trick, but especially the second solution is in line with what I was trying to figure out.

I have been searching and searching for how to accomplish this task, so your answer is greatly appreciated! I will give it a go and let you know.

Thank you, thank you, thank you!!!

-Kari

---

<div class="post-metadata">

**Author:** ![samliew](https://dub1.discourse-cdn.com/flex013/user_avatar/community.make.com/samliew/32/13327_2.png) [@samliew](https://community.make.com/u/samliew)\
**Post date:** [September 1, 2023, 4:16am UTC](https://community.make.com/t/incoming-webhook-authentication/15219/6 "2023-09-01T04:16:36Z")

</div>

No problem, glad I could help!

The [Make Community guidelines](https://community.make.com/t/make-community-the-ultimate-topic/11682) encourages users to try to **mark helpful replies as solutions** to help keep the Community organized.

This marks the topic as solved, so that:

- others can _save time_ when catching up with the latest activity here, and
- allows others to _quickly jump to the solution_ if they come across the same problem

To do this, simply click the checkbox at the bottom of the post:

> ![screenshot](https://europe1.discourse-cdn.com/flex013/uploads/make/original/2X/f/fac9e179e7c5b9e1d7908e106b5b1ae1e7d39d5b.png)

Once you’ve given it a go and found that the solution suits your requirements, hope you can return to provide any additional feedback and close off this thread.

---

<div class="post-metadata">

**Author:** ![Kari\_G](https://avatars.discourse-cdn.com/v4/letter/k/ed655f/32.png) [@Kari\_G](https://community.make.com/u/Kari_G)\
**Post date:** [September 1, 2023, 4:34am UTC](https://community.make.com/t/incoming-webhook-authentication/15219/7 "2023-09-01T04:34:21Z")

</div>

Thank you for letting me know about this community guideline! I will be sure to come back and give an update about how things went, mark the solution, and close the thread.

Thank you again for everything!

-Kari

---

<div class="post-metadata">

**Author:** ![Kari\_G](https://avatars.discourse-cdn.com/v4/letter/k/ed655f/32.png) [@Kari\_G](https://community.make.com/u/Kari_G)\
**Post date:** [September 2, 2023, 4:41am UTC](https://community.make.com/t/incoming-webhook-authentication/15219/8 "2023-09-02T04:41:53Z")

</div>

Hi @samliew ,

I just can’t thank you enough for your help! Your solution worked like a charm! I used the second API Key authentication example you gave me. Thank you also for the tip about the Enterprise plan - that will make things easier too.

I’m going to expound on your solution with a few screenshots in case anyone else, who is trying to set up webhook authentication and also test with Postman, comes across this post.

Thank you again for your help and for getting back to me so quickly! You saved me a lot of time and extra frustration - I was already careening toward frustration when I reached out! 😅 What a great resource this community is!

-Kari

* * *

Here is my Postman API Key authentication setup:

 ![Postman_API_Key_Auth_Setup](https://europe1.discourse-cdn.com/flex013/uploads/make/original/2X/2/27f2ac3c858464875e1c3246f72eb42d09d3728d.png)

In the webhook, I toggled “Show advanced settings” on and made sure “Get request headers” was set to “Yes.”

 ![Set_Get_Request_Headers_to_Yes](https://europe1.discourse-cdn.com/flex013/uploads/make/original/2X/7/76e31f3fbcfe552c17172d088238a4c3f5335be2.png)

Here’s where I put the “Key” (arbitrary key name) and “Value” (arbitrary password) from Postman into the filter you showed me how to set up:

 ![API_Key_Filter_Settings](https://europe1.discourse-cdn.com/flex013/uploads/make/original/2X/5/5404330e68389daf0f09c2df673059c35ea5f76c.png)

This is what the scenario looked like when the filter did its job (password didn’t match, authentication failed - filter icon has “0” badge, and payload did not pass to the next module.)

 ![Filter_Has_0_Badge_When_Authentication_Fails](https://europe1.discourse-cdn.com/flex013/uploads/make/original/2X/9/961452e2a2230095bd4388e2970ed23d657208bd.png)

This is what the scenario looked like when the password matched (authentication passed, and payload was passed to the next module.)

 ![Filter_Has_1_Badge_When_Authentication_Passes](https://europe1.discourse-cdn.com/flex013/uploads/make/original/2X/6/64b3cf63df62c75d7f3399d38bad83dc329246e2.png)

---

<div class="post-metadata">

**Author:** ![samliew](https://dub1.discourse-cdn.com/flex013/user_avatar/community.make.com/samliew/32/13327_2.png) [@samliew](https://community.make.com/u/samliew)\
**Post date:** [September 2, 2023, 5:26am UTC](https://community.make.com/t/incoming-webhook-authentication/15219/9 "2023-09-02T05:26:49Z")

</div>

Excellent! I’m glad to hear that you got the Header authentication method working, and thanks for sharing screenshots of your setup, which is very helpful to others who may also consider securing their webhooks this way.

---

<div class="post-metadata">

**Author:** ![Make\_Bot](https://dub1.discourse-cdn.com/flex013/user_avatar/community.make.com/make_bot/32/14661_2.png) [@Make\_Bot](https://community.make.com/u/Make_Bot)\
**Post date:** [September 22, 2023, 4:10pm UTC](https://community.make.com/t/incoming-webhook-authentication/15219/10 "2023-09-22T16:10:08Z")

</div>


