The signed proof your webhook integrity holds — from first line to final audit.
A real, KMS-signed evidence pack — tamper-evident hash chain, SOC 2 + ISO 27001 control mappings, and the EU AI Act Annex III high-risk classification. Download it, verify it offline, hand it to your auditor.
Webhook integrity. From first line to final audit. evidence-pack · v1.1
eu_ai_act_annex_iii high_risk_ai_system
audit-log hash chain · 3 rows
seq 1 evidence_pack_exported hash 769709b1e4c8… prev ∅ genesis
seq 2 rotation_finalized hash 81796f8d3979… prev 769709b1e4c8…
seq 3 auditor_token_used hash 4e3109194345… prev 81796f8d3979…
signing_algorithmECDSA_SHA_256
manifest_hash_hex383a277f9be8f3a82a21e1a7…
signature_der_b64MEYCIQCdExkLEZ5RdYDb3Rgu…
the full pack (canonical JSON)
{
"eu_ai_act_annex_iii": "high_risk_ai_system",
"exported_at": "2026-08-02T00:00:00.000Z",
"iso27001_mapping": {
"A.5.17": [
"leak-aws-key-cloudwatch-001",
"finding-stripe-no-verify-001",
"finding-github-replay-002"
],
"A.8.24": [
"rotation-stripe-whsec-001",
"finding-stripe-no-verify-001",
"finding-github-replay-002"
]
},
"pack_id": "sample-eu-ai-act-v1.1",
"schema_version": "1.1",
"scope": {
"audit_log": {
"rows": [
{
"createdAt": "2026-08-01T09:00:00.000Z",
"hashHex": "769709b1e4c8f290e71098f8b40994aa5e8ea620d96f7bcda3d6739d08eeecfe",
"kind": "evidence_pack_exported",
"payload": {
"actor_user_id": "auditor-illustrative",
"pack_id": "prior-export-000"
},
"prevHashHex": null,
"seq": "1"
},
{
"createdAt": "2026-08-01T10:15:00.000Z",
"hashHex": "81796f8d39792194afd536de9956f51bee2c195c6568b7addb055b26ea9f82f2",
"kind": "rotation_finalized",
"payload": {
"endpoint": "ep-illustrative-001",
"provider": "stripe",
"rotation_id": "rotation-stripe-whsec-001"
},
"prevHashHex": "769709b1e4c8f290e71098f8b40994aa5e8ea620d96f7bcda3d6739d08eeecfe",
"seq": "2"
},
{
"createdAt": "2026-08-01T11:30:00.000Z",
"hashHex": "4e3109194345d6a9f760a89a7b086ea6e42325cd1b1f8df7ee94da277a816548",
"kind": "auditor_token_used",
"payload": {
"page_path": "/auditor/sample",
"token_id": "auditor-token-illustrative"
},
"prevHashHex": "81796f8d39792194afd536de9956f51bee2c195c6568b7addb055b26ea9f82f2",
"seq": "3"
}
],
"signed_batches": []
},
"endpoints": [
{
"id": "ep-illustrative-001",
"provider": "stripe",
"url_path": "/api/webhooks/stripe",
"verification": "hmac_sha256"
}
],
"findings": [
{
"file_line": "src/routes/webhooks.ts:42",
"id": "finding-stripe-no-verify-001",
"rule_id": "stripe/no-signature-verification",
"severity": "critical",
"state": "fixed"
},
{
"file_line": "src/webhooks/github.ts:88",
"id": "finding-github-replay-002",
"rule_id": "github/missing-replay-protection",
"severity": "high",
"state": "persisting"
}
],
"leaks": [],
"rotations": []
},
"soc2_mapping": {
"CC6.1": [
"leak-aws-key-cloudwatch-001"
],
"CC6.7": [
"finding-stripe-no-verify-001",
"finding-github-replay-002"
],
"CC7.1": [
"rotation-stripe-whsec-001"
]
},
"workspace_id": "00000000-0000-4000-8000-000000000026"
} Don't trust us — verify it.
The downloaded pack passes this offline verifier with no network call:
curl -sO https://hookwarden.dev/verify-evidence-pack.mjs -sO https://hookwarden.dev/sample-pack.json && npm i @hookwarden/canonical-json && node verify-evidence-pack.mjs --pack sample-pack.json Same byte-for-byte verifier an auditor runs on a production export — the sample carries an embedded public key, so it verifies with zero AWS calls.
PROVE
hookwarden also ships an MCP server, so AI coding agents can check webhook signature verification while they write the handler.