Provider reference / Vercel

How Vercel delivers webhooks

Vercel signs the raw body with HMAC-SHA1. The verified format, the unpublished delivery behaviour, and a Node verifier.

Delivery behaviour

Read from the vendor's own documentation, last checked 2026-08-06. Where the vendor states no number, this table carries none.

Response budgetnot published by the vendor
Retrynot published by the vendor
Gives upnot published by the vendor

Signature

Verified against a working verifier proven by a test suite, not read from documentation. Last verified 2026-08-20.

AlgorithmHMAC-SHA1
Signed payloadraw body
Encodinghex
Headerx-vercel-signature
Tolerancenone enforced

Verify it

The raw request body, byte for byte, before any JSON parsing. Every scheme on this page breaks the moment a framework re-serializes the payload.

const crypto = require("node:crypto");

// hex(HMAC-SHA1(webhook secret, raw body))
const expected = crypto
  .createHmac("sha1", webhookSecret) // Team Settings → Webhooks, shown once
  .update(rawBody)
  .digest("hex");
const valid = crypto.timingSafeEqual(
  Buffer.from(req.headers["x-vercel-signature"]),
  Buffer.from(expected),
);

What bites

The secret is shown exactly once, at creation. Lose it and the only path is deleting and re-creating the webhook — there is no reveal button to go back to.

Read more

AnyHook sits in front of endpoints that receive from Vercel: it answers inside the budget above, retries on its own schedule when your server is down, and keeps every event replayable. Change one URL, keep your code.

How it works →